Description
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kses bypass / mutation XSS in all versions up to, and including, 3.28.36. This is due to the 'get_dynamic_values' function performing text-level find-and-replace operations on post content without HTML-aware parsing. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-10-10
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS
Action: Apply Patch
AI Analysis

Impact

The Frontend Admin by DynamiApps WordPress plugin contains a stored cross‑site scripting flaw caused by a kses bypass. The vulnerability is driven by the get_dynamic_values function, which performs a simple text replacement on post content without proper HTML‑aware parsing. An attacker with Contributor or higher privileges can inject arbitrary JavaScript into post bodies, which will execute for all users who view the affected pages.

Affected Systems

WordPress sites that have the Frontend Admin by DynamiApps plugin installed in any version up to and including 3.28.36. The plugin is maintained by DynamiApps and the impact applies to installations that have not yet upgraded beyond this version.

Risk and Exploitability

The attack takes place from an authenticated user with at least Contributor access. Based on the description, it is inferred that the attacker must create or edit a post via the plugin’s front‑end form and supply malicious script payloads that bypass the plugin’s filtering. Once stored, the script executes in the browser whenever the post is viewed, enabling session hijacking, phishing, or other client‑side attacks. The CVSS score of 6.4 indicates moderate severity. The EPSS score is not available, so the likelihood of exploitation is uncertain, and the vulnerability is not listed in the CISA KEV catalog. Because exploitation requires authenticated site access, the risk is limited to contributors and site users, but the impact on all site visitors who view the affected content can be significant.

Generated by OpenCVE AI on October 10, 2026 at 08:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the plugin to version 3.28.37 or later to remove the vulnerable get_dynamic_values function.
  • If an upgrade is not immediately possible, disable Contributor or higher users from editing or creating posts through the plugin’s front‑end form, or remove the form functionality entirely for the affected time period.
  • Apply stricter content sanitization by integrating WordPress KSES or a third‑party library to filter out script tags before storing post content.

Generated by OpenCVE AI on October 10, 2026 at 08:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kses bypass / mutation XSS in all versions up to, and including, 3.28.36. This is due to the 'get_dynamic_values' function performing text-level find-and-replace operations on post content without HTML-aware parsing. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Frontend Admin by DynamiApps <= 3.28.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Content
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T06:40:13.833Z

Reserved: 2026-04-13T17:16:30.790Z

Link: CVE-2026-6243

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T07:16:41.783

Modified: 2026-10-10T07:16:41.783

Link: CVE-2026-6243

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T08:30:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')