Description
Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.
Published: 2026-08-06
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a broken access control flaw that allows a user with subscriber privileges to perform actions normally restricted to higher‑privileged roles. This type of flaw is classified as CWE‑862. An attacker exploiting this weakness could gain unauthorized access to sensitive data, modify content, or impersonate users with elevated privileges, thereby compromising the confidentiality, integrity, and possibly availability of the WordPress site. The impact extends to any subscriber account that is authenticated and logged into the site.

Affected Systems

WordPress sites that have the Frontend Admin by DynamiApps plugin from the vendor Shabti Kaplan installed in any version up to and including 3.29.10 are affected. No other vendors or product versions are listed as impacted.

Risk and Exploitability

The issue carries a CVSS score of 7.1, indicating a high severity level. The EPSS score is not available, but the absence of an EPSS rating does not diminish the serious nature of the flaw. The vulnerability is not listed in CISA’s KEV catalog. Attackers can leverage the flaw via the normal web interface that subscribers use, making it potentially exploitable remotely by anyone with subscriber access. No specific exploit code has been publicized, but the nature of the flaw means that an attacker could manually trigger the unauthorized actions through the plugin’s frontend interface.

Generated by OpenCVE AI on August 6, 2026 at 16:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Frontend Admin by DynamiApps plugin to version 3.29.11 or newer
  • If an immediate update is not possible, deactivate or uninstall the plugin temporarily to block access to the vulnerable functionality
  • Use a role management plugin to remove or limit subscriber role capabilities that allow access to the plugin’s front‑end admin pages, thereby reducing the attack surface.

Generated by OpenCVE AI on August 6, 2026 at 16:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Shabti
Shabti frontend Admin By Dynamapps
Wordpress
Wordpress wordpress
Vendors & Products Shabti
Shabti frontend Admin By Dynamapps
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.
Title WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

Shabti Frontend Admin By Dynamapps
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T15:35:36.809Z

Reserved: 2026-07-27T09:00:40.310Z

Link: CVE-2026-66470

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-06T15:17:20.720

Modified: 2026-08-12T20:58:37.847

Link: CVE-2026-66470

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T20:54:00Z

Weaknesses