PHP Object Injection Vulnerability in DynamiApps WordPress Plugin
CVE-2026-3328
7.2HIGH
What is CVE-2026-3328?
The Frontend Admin plugin by DynamiApps for WordPress is vulnerable to PHP Object Injection through deserialization of user-controlled data in the 'post_content' field of admin_form posts. This flaw arises from the improper use of the maybe_unserialize() function, which lacks restrictions on class types. Authenticated attackers with Editor-level access or higher can exploit this vulnerability to inject malicious PHP objects, enabling the execution of arbitrary code within the affected environment.
Affected Version(s)
Frontend Admin by DynamiApps 0 <= 3.28.31