Description
The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated users with low privileges (such as Subscribers) to create, rename, and delete arbitrary taxonomy terms.
Published: 2026-07-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Frontend Admin by DynamiApps WordPress plugin before version 3.29.7 fails to perform capability checks on taxonomy term creation, modification, and deletion. An authenticated user with low privileges, such as a Subscriber, can therefore add, rename, or delete arbitrary taxonomy terms. This can be used to hide, redirect, or manipulate content organization, potentially compromising the site’s integrity and presentation.

Affected Systems

Any WordPress site running the Frontend Admin by DynamiApps plugin with a version earlier than 3.29.7 is affected.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.5, indicating moderate severity. The EPSS score is less than 1 %, suggesting a low likelihood of exploitation at present. It is not listed in the CISA KEV catalog. The attack vector requires that the attacker is an authenticated user with a low‑privilege role, as described in the CVE description; no further prerequisites are specified. If an attacker can assume a Subscriber account, they can manipulate taxonomy terms without authorization.

Generated by OpenCVE AI on August 3, 2026 at 11:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Frontend Admin by DynamiApps to version 3.29.7 or later, which includes the missing authorization checks.
  • Disable or uninstall the plugin if it is not required for site functionality.
  • Adjust the Subscriber role (or relevant low‑privilege roles) to remove permissions for taxonomy term creation, modification, and deletion, using a role editor or custom code.

Generated by OpenCVE AI on August 3, 2026 at 11:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Dynamiapps
Dynamiapps frontend Admin
Wordpress
Wordpress wordpress
Vendors & Products Dynamiapps
Dynamiapps frontend Admin
Wordpress
Wordpress wordpress

Thu, 30 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated users with low privileges (such as Subscribers) to create, rename, and delete arbitrary taxonomy terms.
Title Frontend Admin by DynamiApps < 3.29.7 - Subscriber+ Taxonomy Term Creation/Modification/Deletion via Missing Authorization
References

Subscriptions

Dynamiapps Frontend Admin
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-30T16:02:33.029Z

Reserved: 2026-06-10T12:15:30.132Z

Link: CVE-2026-11867

cve-icon Vulnrichment

Updated: 2026-07-30T16:01:52.169Z

cve-icon NVD

Status : Deferred

Published: 2026-07-30T06:24:58.203

Modified: 2026-07-30T16:45:00.353

Link: CVE-2026-11867

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T11:15:04Z

Weaknesses