SQL Injection Vulnerability in Frontend Admin Plugin by DynamiApps for WordPress
CVE-2026-10039
4.9MEDIUM
What is CVE-2026-10039?
The Frontend Admin plugin by DynamiApps for WordPress is susceptible to SQL Injection vulnerabilities due to inadequate escaping of user-supplied inputs. This flaw allows authenticated attackers with administrator-level access to manipulate existing SQL queries by injecting additional commands through the 'order' parameter. Successful exploitation hinges on also providing a valid 'orderby' parameter, which leads to the execution of compromised SQL code intended to extract sensitive database information. This vulnerability highlights the urgent need for developers to implement stringent input validation and query preparation practices to safeguard against potential data breaches.
Affected Version(s)
Frontend Admin by DynamiApps 0 <= 3.28.8