Description
Administrator SQL Injection in Frontend Admin by DynamiApps <= 3.29.13 versions.
Published: 2026-10-10
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: Remote SQL Injection
Action: Immediate Patch
AI Analysis

Impact

An unsanitized input field in the WordPress Frontend Admin by DynamiApps plugin allows administrators to inject arbitrary SQL statements, which can lead to unauthorized database read, modification, or deletion. The flaw is a classic SQL injection (CWE‑89) that can compromise the confidentiality and integrity of the site’s data and potentially enable further privilege escalation.

Affected Systems

WordPress sites using the Frontend Admin by DynamiApps plugin from vendor Shabti Kaplan, versions 3.29.13 and earlier are vulnerable. The specific plugin and all earlier releases below 3.29.14 are impacted.

Risk and Exploitability

The CVSS score of 7.6 classifies this flaw as high severity, indicating that exploitation would have significant impact if an attacker can reach the vulnerable input. EPSS data is not available, preventing a precise probability assessment, but the plugin’s web‑based forms make remote exploitation plausible. The vulnerability is not listed in the CISA KEV catalog, yet the high CVSS and remote nature warrant immediate attention.

Generated by OpenCVE AI on October 10, 2026 at 20:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Frontend Admin by DynamiApps plugin to version 3.29.14 or later to remove the injection code paths.
  • Restrict access to the plugin’s front‑end forms so only authenticated, authorized users can submit data.
  • Implement input validation or a web application firewall to detect and block malicious SQL payloads before they reach the database.

Generated by OpenCVE AI on October 10, 2026 at 20:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Administrator SQL Injection in Frontend Admin by DynamiApps <= 3.29.13 versions.
Title WordPress Frontend Admin by DynamiApps plugin <= 3.29.13 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T19:35:19.708Z

Reserved: 2026-04-29T09:05:20.866Z

Link: CVE-2026-42722

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T20:16:37.150

Modified: 2026-10-10T20:16:37.150

Link: CVE-2026-42722

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T20:45:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')