cleantalk
Vulnerabilities and Security Researches

Frontend Admin by DynamiApps, CVE-2026-11867

CVE, Research URL

CVE-2026-11867

Published on
Jul 30, 2026
Research Description
The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated users with low privileges (such as Subscribers) to create, rename, and delete arbitrary taxonomy terms.
Affected versions
max 3.29.7.
Status
vulnerable