Authorization Bypass in Frontend Admin Plugin for WordPress by DynamiApps
CVE-2026-7802

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
28 May 2026

What is CVE-2026-7802?

The Frontend Admin plugin for WordPress is susceptible to an authorization bypass flaw. This vulnerability allows authenticated attackers with subscriber-level access and higher to manipulate user accounts. By exploiting this weakness, attackers can change critical user information such as an administrator's password, email, and profile details simply by supplying a specific user ID. This attack is contingent upon the Edit-User form's 'Roles' setting being empty; otherwise, safeguards prevent unauthorized access. It's essential for users to update to the latest version to mitigate this risk.

Affected Version(s)

Frontend Admin by DynamiApps 0 <= 3.29.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tiago Ventura
.