Authentication Bypass in Frontend Admin Plugin by DynamiApps for WordPress
CVE-2026-75816

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 September 2026

What is CVE-2026-75816?

The Frontend Admin plugin by DynamiApps for WordPress is susceptible to an authentication bypass that can lead to account takeover. All versions up to and including 3.29.12 are impacted. This vulnerability arises from the lack of capability checks in the 'pre_update_value' function, and inadequate authorization in 'ActionPost::conditions_logic()', which bypasses essential user permissions when a non-numeric post ID is provided. As a result, attackers can submit unauthenticated forms to modify arbitrary user records, including updating an admin's registered email. Consequently, they can exploit WordPress’s password reset feature to gain complete control over targeted accounts.

Affected Version(s)

Frontend Admin by DynamiApps 0 <= 3.29.12

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

thevietronin
.