Description
The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans.
Published: 2026-08-29
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Membership Plan Deletion
Action: Patch
AI Analysis

Impact

The Frontend Admin by DynamiApps WordPress plugin, versions prior to 3.29.11, performs a membership plan deletion through an AJAX action without checking whether the user has the proper capability. Because this action is available to any authenticated user, even site subscribers, an attacker can trigger the deletion of any membership plan that the site administrator has created. The removal of a plan deletes definition from the database, invalidating any entitlements or billing logic that depended on that plan and potentially disrupting the site’s subscription model.

Affected Systems

WordPress installations that install the Frontend Admin by DynamiApps plugin and are running a version earlier than 3.29.11 are affected. The vulnerability applies to all prior releases for which the capability check is missing; all older versions should be regarded as potentially vulnerable because no sub‑version updates are specified.

Risk and Exploitability

An authenticated user with subscriber role can send a crafted AJAX request to the vulnerable endpoint and delete a membership plan. The exploit requires no elevated server privileges, can be performed remotely over the web, and does not need specific network or local access. The CVSS score of 4.3 reflects a moderate severity due mainly to the limited impact of plan deletion. The EPSS score of less than 1% and its absence from the CISA KEV catalog indicate a low likelihood of widespread exploitation, though the flaw is trivial for a legitimate user to use.

Generated by OpenCVE AI on August 30, 2026 at 05:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Frontend Admin by DynamiApps to version 3.29.11 or later to restore the missing capability check.
  • Revoke the ability for subscriber users to trigger the delete plan AJAX action by removing the delete capability from the subscriber role or by using a role‑management plugin to limit dashboard access.
  • Install an audit or monitoring tool that logs membership plan deletion events, so any unauthorized deletions can be identified and investigated promptly.

Generated by OpenCVE AI on August 30, 2026 at 05:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Dynamiapps
Dynamiapps frontend Admin By Dynamiapps
Wordpress
Wordpress wordpress
Vendors & Products Dynamiapps
Dynamiapps frontend Admin By Dynamiapps
Wordpress
Wordpress wordpress

Sun, 30 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 30 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 29 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 29 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans.
Title Frontend Admin by DynamiApps < 3.29.11 - Subscriber+ Arbitrary Membership Plan Deletion
References

Subscriptions

Dynamiapps Frontend Admin By Dynamiapps
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-30T00:56:50.071Z

Reserved: 2026-08-26T18:17:25.366Z

Link: CVE-2026-81346

cve-icon Vulnrichment

Updated: 2026-08-30T00:48:26.199Z

cve-icon NVD

Status : Deferred

Published: 2026-08-29T06:18:02.633

Modified: 2026-08-31T20:14:36.250

Link: CVE-2026-81346

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:16:57Z

Weaknesses