Authentication Bypass in Frontend Admin Plugin by DynamiApps for WordPress
CVE-2026-75816
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 September 2026
What is CVE-2026-75816?
The Frontend Admin plugin by DynamiApps for WordPress is susceptible to an authentication bypass that can lead to account takeover. All versions up to and including 3.29.12 are impacted. This vulnerability arises from the lack of capability checks in the 'pre_update_value' function, and inadequate authorization in 'ActionPost::conditions_logic()', which bypasses essential user permissions when a non-numeric post ID is provided. As a result, attackers can submit unauthenticated forms to modify arbitrary user records, including updating an admin's registered email. Consequently, they can exploit WordPress’s password reset feature to gain complete control over targeted accounts.
Affected Version(s)
Frontend Admin by DynamiApps 0 <= 3.29.12