Stored Cross-Site Scripting Vulnerability in Frontend Admin Plugin by DynamiApps
CVE-2026-12747
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 September 2026
What is CVE-2026-12747?
The Frontend Admin plugin by DynamiApps is prone to a Stored Cross-Site Scripting vulnerability due to inadequate sanitization of the 'tag' shortcode attribute. This flaw allows authenticated attackers with at least contributor-level access to inject malicious scripts. The injected scripts can execute whenever users access compromised pages, posing significant security risks and compromising user data.
Affected Version(s)
Frontend Admin by DynamiApps 0 <= 3.29.11