SQL Injection Vulnerability in Frontend Admin Plugin by DynamiApps for WordPress
CVE-2026-10039

4.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
29 May 2026

What is CVE-2026-10039?

The Frontend Admin plugin by DynamiApps for WordPress is susceptible to SQL Injection vulnerabilities due to inadequate escaping of user-supplied inputs. This flaw allows authenticated attackers with administrator-level access to manipulate existing SQL queries by injecting additional commands through the 'order' parameter. Successful exploitation hinges on also providing a valid 'orderby' parameter, which leads to the execution of compromised SQL code intended to extract sensitive database information. This vulnerability highlights the urgent need for developers to implement stringent input validation and query preparation practices to safeguard against potential data breaches.

Affected Version(s)

Frontend Admin by DynamiApps 0 <= 3.28.8

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Louis Deschanel
Pascal SUN
.