Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-75816: Frontend Admin plugin lets strangers change any user email
CVE-2026-75816 · published 1 month ago
Summary
The Frontend Admin plugin for WordPress (up to version 3.29.12) allows anyone on the internet to modify a user's email address, including administrators'. Once the email is changed, the attacker can use WordPress's normal password reset process to take over that account. Update the plugin to a newer version or remove it until it is patched.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| shabti | frontend admin by dynamiapps | <= 3.29.12 |
Original advisory text
Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_objects' Object Identifier
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check, and ActionPost::conditions_logic() short-circuiting its current_user_can('edit_post') authorization gate whenever the post ID is non-numeric — such as the string user_1 — allowing unauthenticated form submissions to be routed to arbitrary user records without restriction. This makes it possible for unauthenticated attackers to overwrite any user's registered email address, including an administrator's, and then leverage WordPress's native password-reset flow to fully take over the targeted account.
References
- https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.1...
- https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.1...
- https://plugins.trac.wordpress.org/changeset/3664865/acf-frontend-form-element
- https://www.wordfence.com/threat-intel/vulnerabilities/id/f1637a3b-7b0f-485d-9d1...
- https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.1...
- https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.1...
- https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.1...
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-287Improper Authentication
Timeline
Published6 Sep 2026
Updated7 Oct 2026
First seen6 Sep 2026
Track software like this
Free during beta