Authorization Bypass in Frontend Admin Plugin for WordPress by DynamiApps
CVE-2026-7802
8.8HIGH
What is CVE-2026-7802?
The Frontend Admin plugin for WordPress is susceptible to an authorization bypass flaw. This vulnerability allows authenticated attackers with subscriber-level access and higher to manipulate user accounts. By exploiting this weakness, attackers can change critical user information such as an administrator's password, email, and profile details simply by supplying a specific user ID. This attack is contingent upon the Edit-User form's 'Roles' setting being empty; otherwise, safeguards prevent unauthorized access. It's essential for users to update to the latest version to mitigate this risk.
Affected Version(s)
Frontend Admin by DynamiApps 0 <= 3.29.2