Skip to content
Noroxi

Frontend Admin by DynamiApps

acf-frontend-form-element · plugin

Known security vulnerabilities for Frontend Admin by DynamiApps. Find out in seconds which version runs on your site with WP Lens.

25 known vulnerabilities

8 critical · 16 exploitable without logging in · 4 with public exploit code · latest Sep 5, 2026

Listed on wordpress.org · latest 3.29.13 · last updated Aug 25, 2026 · 8K+ installs

wordpress.org status checked on Oct 4, 2026

Vulnerabilities

  • CVE-2026-75816unauthenticated≤ 3.29.12

    Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_objects' Object Identifier

    Critical 9.8
  • CVE-2026-18432unauthenticated≤ 3.29.9

    Frontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_id' Parameter

    Critical 9.8
  • CVE-2026-66662unauthenticated≤ 3.29.10

    WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Privilege Escalation vulnerability

    Critical 9.8
  • CVE-2025-14736unauthenticated≤ 3.28.29

    Frontend Admin by DynamiApps <= 3.28.29 - Unauthenticated Privilege Escalation to Administrator via Role Form Field

    Critical 9.8
  • CVE-2025-13342unauthenticated≤ 3.28.20

    Frontend Admin by DynamiApps <= 3.28.20 - Unauthenticated Arbitrary Options Update

    Critical 9.8
  • CVE-2024-3729unauthenticated≤ 3.19.4

    Frontend Admin by DynamiApps <= 3.19.4 - Improper Missing Encryption Exception Handling to Form Manipulation

    Critical 9.8
  • CVE-2023-51411unauthenticated≤ 3.18.3

    WordPress Frontend Admin by DynamiApps Plugin <= 3.18.3 is vulnerable to Arbitrary File Upload

    Critical 9.8
  • CVE-2025-14741unauthenticated≤ 3.28.25

    Frontend Admin by DynamiApps <= 3.28.25 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via 'delete post' Form Element

    Critical 9.1
  • CVE-2026-6226unauthenticated≤ 3.29.2

    Frontend Admin by DynamiApps <= 3.29.2 - Unauthenticated Privilege Escalation via Form Configuration Injection

    High 8.8
  • CVE-2026-6228unauthenticated≤ 3.28.36

    Frontend Admin by DynamiApps <= 3.28.36 - Unauthenticated Privilege Escalation via Edit User Form

    High 8.8
  • CVE-2026-15606subscriber+≤ 3.29.9

    Frontend Admin by DynamiApps <= 3.29.9 - Authenticated (Subscriber+) Arbitrary Password Reset via Encrypted Object Token

    High 8.8
  • CVE-2026-7802subscriber+≤ 3.29.2

    Frontend Admin by DynamiApps <= 3.29.2 - Missing Authorization to Authenticated (Subscriber+) Account Takeover via 'user_id' URL Query Parameter

    High 8.8
  • CVE-2025-49267login required≤ 3.28.3

    WordPress Frontend Admin by DynamiApps plugin <= 3.28.3 - SQL Injection vulnerability

    High 8.5
  • CVE-2024-11721unauthenticated≤ 3.24.5

    Frontend Admin by DynamiApps <= 3.24.5 - Unauthenticated Privilege Escalation

    High 8.1
  • CVE-2026-19952unauthenticated≤ 3.29.12

    Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Arbitrary File Deletion via Path Traversal via custom_directory_name Merge Tag

    High 7.5
  • CVE-2025-14937unauthenticated≤ 3.28.23

    Frontend Admin by DynamiApps <= 3.28.23 - Unauthenticated Stored Cross-Site Scripting via 'update_field'

    High 7.2
  • CVE-2026-3328editor+≤ 3.28.31

    Frontend Admin by DynamiApps <= 3.28.31 - Authenticated (Editor+) PHP Object Injection via 'post_content' of Admin Form Posts

    High 7.2
  • CVE-2026-66470subscriber+≤ 3.29.10

    WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Broken Access Control vulnerability

    High 7.1
  • CVE-2025-49303high privilege≤ 3.28.7

    WordPress Frontend Admin by DynamiApps plugin <= 3.28.7 - Arbitrary File Download Vulnerability

    Medium 6.8
  • CVE-2026-66638contributor+≤ 3.29.10

    WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Cross Site Scripting (XSS) vulnerability

    Medium 6.5
  • CVE-2026-12747contributor+≤ 3.29.11

    Frontend Admin by DynamiApps <= 3.29.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Shortcode Attribute

    Medium 6.4
  • CVE-2025-26987unauthenticated · needs a click≤ 3.25.17

    WordPress Frontend Admin by DynamiApps plugin <= 3.25.17 - Reflected Cross Site Scripting (XSS) vulnerability

    Medium 6.1
  • CVE-2024-11720unauthenticated≤ 3.24.5

    Frontend Admin by DynamiApps <= 3.24.5 - Unauthenticated Stored Cross-Site Scripting

    Medium 6.1
  • CVE-2024-11722unauthenticated≤ 3.25.1

    Frontend Admin by DynamiApps <= 3.25.1 - Unauthenticated SQL Injection

    Medium 5.9
  • CVE-2026-10039admin≤ 3.28.8

    Frontend Admin by DynamiApps <= 3.28.28 - Authenticated (Administrator+) SQL Injection via 'order' Parameter

    Medium 4.9

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory