Description
Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
Published: 2026-08-06
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated user to gain administrative privileges within a WordPress site that uses the Frontend Admin by DynamiApps plugin. By exploiting a flaw in the plugin’s access control, an attacker can elevate their privileges to a level that can modify site content, manage settings, and potentially execute arbitrary code. This increase in privileges undermines confidentiality, integrity, and availability of the website.

Affected Systems

Any WordPress site running the Frontend Admin by DynamiApps plugin version 3.29.10 or earlier is affected. The exact API endpoints or page paths are not detailed, but any instance of the vulnerable plugin installation is at risk.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity. EPSS is not available, and the vulnerability is not listed in CISA KEV, suggesting a lower known exploitation prevalence. Although the exact attack vector is not specified, it is inferred that the vulnerability can be exploited via the plugin’s frontend interfaces, which are publicly accessible, allowing an unauthenticated attacker to trigger the privilege escalation by interacting with the plugin’s exposed forms or URLs.

Generated by OpenCVE AI on August 6, 2026 at 15:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Frontend Admin by DynamiApps plugin to a version newer than 3.29.10 to resolve the privilege escalation flaw.
  • If an upgrade is not feasible, disable or uninstall the plugin from the WordPress install to prevent exploitation.
  • Deploy a web application firewall rule that blocks known patterns associated with the Frontend Admin plugin to mitigate potential exploitation attempts.

Generated by OpenCVE AI on August 6, 2026 at 15:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Shabti
Shabti frontend Admin By Dynamapps
Wordpress
Wordpress wordpress
Vendors & Products Shabti
Shabti frontend Admin By Dynamapps
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
Title WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Shabti Frontend Admin By Dynamapps
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T14:57:28.613Z

Reserved: 2026-07-27T14:00:43.008Z

Link: CVE-2026-66662

cve-icon Vulnrichment

Updated: 2026-08-06T14:57:24.861Z

cve-icon NVD

Status : Deferred

Published: 2026-08-06T15:17:20.850

Modified: 2026-08-12T20:59:00.027

Link: CVE-2026-66662

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T20:53:59Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment