Frontend Admin by DynamiApps
acf-frontend-form-element · plugin
Known security vulnerabilities for Frontend Admin by DynamiApps. Find out in seconds which version runs on your site with WP Lens.
25 known vulnerabilities
8 critical · 16 exploitable without logging in · 4 with public exploit code · latest Sep 5, 2026
Listed on wordpress.org · latest 3.29.13 · last updated Aug 25, 2026 · 8K+ installs
wordpress.org status checked on Oct 4, 2026
Vulnerabilities
- Critical 9.8
CVE-2026-75816unauthenticated≤ 3.29.12
Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_objects' Object Identifier
- Critical 9.8
CVE-2026-18432unauthenticated≤ 3.29.9
Frontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_id' Parameter
- Critical 9.8
CVE-2026-66662unauthenticated≤ 3.29.10
WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Privilege Escalation vulnerability
- Critical 9.8
CVE-2025-14736unauthenticated≤ 3.28.29
Frontend Admin by DynamiApps <= 3.28.29 - Unauthenticated Privilege Escalation to Administrator via Role Form Field
- Critical 9.8
CVE-2025-13342unauthenticated≤ 3.28.20
Frontend Admin by DynamiApps <= 3.28.20 - Unauthenticated Arbitrary Options Update
- Critical 9.8
CVE-2024-3729unauthenticated≤ 3.19.4
Frontend Admin by DynamiApps <= 3.19.4 - Improper Missing Encryption Exception Handling to Form Manipulation
- Critical 9.8
CVE-2023-51411unauthenticated≤ 3.18.3
WordPress Frontend Admin by DynamiApps Plugin <= 3.18.3 is vulnerable to Arbitrary File Upload
- Critical 9.1
CVE-2025-14741unauthenticated≤ 3.28.25
Frontend Admin by DynamiApps <= 3.28.25 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via 'delete post' Form Element
- High 8.8
CVE-2026-6226unauthenticated≤ 3.29.2
Frontend Admin by DynamiApps <= 3.29.2 - Unauthenticated Privilege Escalation via Form Configuration Injection
- High 8.8
CVE-2026-6228unauthenticated≤ 3.28.36
Frontend Admin by DynamiApps <= 3.28.36 - Unauthenticated Privilege Escalation via Edit User Form
- High 8.8
CVE-2026-15606subscriber+≤ 3.29.9
Frontend Admin by DynamiApps <= 3.29.9 - Authenticated (Subscriber+) Arbitrary Password Reset via Encrypted Object Token
- High 8.8
CVE-2026-7802subscriber+≤ 3.29.2
Frontend Admin by DynamiApps <= 3.29.2 - Missing Authorization to Authenticated (Subscriber+) Account Takeover via 'user_id' URL Query Parameter
- High 8.5
CVE-2025-49267login required≤ 3.28.3
WordPress Frontend Admin by DynamiApps plugin <= 3.28.3 - SQL Injection vulnerability
- High 8.1
CVE-2024-11721unauthenticated≤ 3.24.5
Frontend Admin by DynamiApps <= 3.24.5 - Unauthenticated Privilege Escalation
- High 7.5
CVE-2026-19952unauthenticated≤ 3.29.12
Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Arbitrary File Deletion via Path Traversal via custom_directory_name Merge Tag
- High 7.2
CVE-2025-14937unauthenticated≤ 3.28.23
Frontend Admin by DynamiApps <= 3.28.23 - Unauthenticated Stored Cross-Site Scripting via 'update_field'
- High 7.2
CVE-2026-3328editor+≤ 3.28.31
Frontend Admin by DynamiApps <= 3.28.31 - Authenticated (Editor+) PHP Object Injection via 'post_content' of Admin Form Posts
- High 7.1
CVE-2026-66470subscriber+≤ 3.29.10
WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Broken Access Control vulnerability
- Medium 6.8
CVE-2025-49303high privilege≤ 3.28.7
WordPress Frontend Admin by DynamiApps plugin <= 3.28.7 - Arbitrary File Download Vulnerability
- Medium 6.5
CVE-2026-66638contributor+≤ 3.29.10
WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Cross Site Scripting (XSS) vulnerability
- Medium 6.4
CVE-2026-12747contributor+≤ 3.29.11
Frontend Admin by DynamiApps <= 3.29.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Shortcode Attribute
- Medium 6.1
CVE-2025-26987unauthenticated · needs a click≤ 3.25.17
WordPress Frontend Admin by DynamiApps plugin <= 3.25.17 - Reflected Cross Site Scripting (XSS) vulnerability
- Medium 6.1
CVE-2024-11720unauthenticated≤ 3.24.5
Frontend Admin by DynamiApps <= 3.24.5 - Unauthenticated Stored Cross-Site Scripting
- Medium 5.9
CVE-2024-11722unauthenticated≤ 3.25.1
Frontend Admin by DynamiApps <= 3.25.1 - Unauthenticated SQL Injection
- Medium 4.9
CVE-2026-10039admin≤ 3.28.8
Frontend Admin by DynamiApps <= 3.28.28 - Authenticated (Administrator+) SQL Injection via 'order' Parameter
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).