Frontend Admin by DynamiApps, CVE-2026-81346
- CVE, Research URL
- Home page URL
- Application
- Published on
- Aug 29, 2026
- Research Description
- The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans.
- Affected versions
-
max 3.29.11.
- Status
-
vulnerable