Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-18432: Frontend Admin by DynamiApps plugin for WordPress allows unauthorized access to admin accounts
CVE-2026-18432 · published 19 days ago
Summary
The Frontend Admin plugin for WordPress has a security flaw that lets attackers gain access to administrator accounts. This can happen when a malicious user submits a specially crafted form on the website. To fix this, update the plugin to the latest version or uninstall it if you don't need it.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| shabti | frontend admin by dynamiapps | <= 3.29.9 |
Original advisory text
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_lo...
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the check to be skipped entirely when `$user_id` is a non-numeric string — a condition that can be induced by passing a crafted value such as `1one` through the unvalidated `item_id` parameter of the unauthenticated `wp_ajax_nopriv_frontend_admin/forms/change_form` AJAX endpoint. This makes it possible for attackers to escalate privileges to administrator by obtaining a server-signed `_acf_objects` payload carrying the non-numeric user ID, which WordPress subsequently coerces to integer 1 (the default administrator), allowing the attacker to overwrite that account's password or email address. Exploitation by unauthenticated users requires a public-facing frontend user form to be configured; in all other cases a subscriber-level account is sufficient.
References
- https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.3...
- https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.3...
- https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.3...
- https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.3...
- https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.3...
- https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.9...
- https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.9...
- https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.9...
- https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.9...
- https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.9...
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3633030%40acf-fronten...
- https://www.wordfence.com/threat-intel/vulnerabilities/id/01404fad-7b5a-485a-b55...
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-269Improper Privilege Management
Timeline
Published16 Aug 2026
Updated3 Sep 2026
First seen16 Aug 2026
Monitor software like this
Free during beta