Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Frontend Admin by DynamiApps — Vulnerabilities & Security Advisories 29

All 29 CVE vulnerabilities found in Frontend Admin by DynamiApps, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability disclosures for the Frontend Admin product developed by DynamiApps, categorizing weaknesses by common vulnerability types such as cross-site scripting and authentication bypass. The collection compiles security advisories and flaw reports issued over the product's available history, focusing on defects that affect web application security. Visitors can track the vendor's security posture over time, analyze recurring weakness classes to identify systemic issues, and review the product's vulnerability history to assess patch frequency and severity trends. This aggregation provides a centralized view of known defects without listing individual CVE identifiers, enabling researchers and administrators to evaluate risk exposure and prioritize remediation efforts effectively.

Vendor: Shabti Kaplan

CVE ID Title CVSS Severity Published
CVE-2026-75816 Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_objects' Object Identifier CWE-287 9.8 Critical 2026-09-06
CVE-2026-81347 Frontend Admin by DynamiApps < 3.29.13 - Unauthenticated .htaccess and index.php Deletion via Custom Directory Path Traversal - - 2026-09-04
CVE-2026-12747 Frontend Admin by DynamiApps <= 3.29.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Shortcode Attribute CWE-79 6.4 Medium 2026-09-01
CVE-2026-19952 Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Arbitrary File Deletion via Path Traversal via custom_directory_name Merge Tag CWE-22 7.5 High 2026-09-01
CVE-2026-81346 Frontend Admin by DynamiApps < 3.29.11 - Subscriber+ Arbitrary Membership Plan Deletion - - 2026-08-29
CVE-2026-66638 WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2026-08-18
CVE-2026-18432 Frontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_id' Parameter CWE-269 9.8 Critical 2026-08-16
CVE-2026-15606 Frontend Admin by DynamiApps <= 3.29.9 - Authenticated (Subscriber+) Arbitrary Password Reset via Encrypted Object Token CWE-862 8.8 High 2026-08-11
CVE-2026-66662 WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Privilege Escalation vulnerability CWE-266 9.8 Critical 2026-08-06
CVE-2026-66470 WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Broken Access Control vulnerability CWE-862 7.1 High 2026-08-06
CVE-2026-13609 Frontend Admin by DynamiApps < 3.29.9 - Unauthenticated Stored Cross-Site Scripting via Form Field - - 2026-07-31
CVE-2026-11867 Frontend Admin by DynamiApps < 3.29.7 - Subscriber+ Taxonomy Term Creation/Modification/Deletion via Missing Authorization - - 2026-07-30
CVE-2026-10039 Frontend Admin by DynamiApps <= 3.28.28 - Authenticated (Administrator+) SQL Injection via 'order' Parameter CWE-89 4.9 Medium 2026-05-29
CVE-2026-6226 Frontend Admin by DynamiApps <= 3.29.2 - Unauthenticated Privilege Escalation via Form Configuration Injection CWE-269 8.8 High 2026-05-28
CVE-2026-7802 Frontend Admin by DynamiApps <= 3.29.2 - Missing Authorization to Authenticated (Subscriber+) Account Takeover via 'user_id' URL Query Parameter CWE-862 8.8 High 2026-05-28
CVE-2026-6228 Frontend Admin by DynamiApps <= 3.28.36 - Unauthenticated Privilege Escalation via Edit User Form CWE-269 8.8 High 2026-05-15
CVE-2026-3328 Frontend Admin by DynamiApps <= 3.28.31 - Authenticated (Editor+) PHP Object Injection via 'post_content' of Admin Form Posts CWE-502 7.2 High 2026-03-26
CVE-2025-14741 Frontend Admin by DynamiApps <= 3.28.25 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via 'delete post' Form Element CWE-862 9.1 Critical 2026-01-09
CVE-2025-14937 Frontend Admin by DynamiApps <= 3.28.23 - Unauthenticated Stored Cross-Site Scripting via 'update_field' CWE-79 7.2 High 2026-01-09
CVE-2025-14736 Frontend Admin by DynamiApps <= 3.28.29 - Unauthenticated Privilege Escalation to Administrator via Role Form Field CWE-269 9.8 Critical 2026-01-09
CVE-2025-13342 Frontend Admin by DynamiApps <= 3.28.20 - Unauthenticated Arbitrary Options Update CWE-862 9.8 Critical 2025-12-03
CVE-2025-49267 WordPress Frontend Admin by DynamiApps plugin <= 3.28.3 - SQL Injection vulnerability CWE-89 8.5 High 2025-08-14
CVE-2025-49303 WordPress Frontend Admin by DynamiApps plugin <= 3.28.7 - Arbitrary File Download Vulnerability CWE-22 6.8 Medium 2025-07-04
CVE-2025-26987 WordPress Frontend Admin by DynamiApps plugin <= 3.25.17 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2025-02-25
CVE-2024-11722 Frontend Admin by DynamiApps <= 3.25.1 - Unauthenticated SQL Injection CWE-89 5.9 Medium 2024-12-21
CVE-2024-11721 Frontend Admin by DynamiApps <= 3.24.5 - Unauthenticated Privilege Escalation CWE-269 8.1 High 2024-12-14
CVE-2024-11720 Frontend Admin by DynamiApps <= 3.24.5 - Unauthenticated Stored Cross-Site Scripting CWE-79 7.2 High 2024-12-14
CVE-2024-3729 Frontend Admin by DynamiApps <= 3.19.4 - Improper Missing Encryption Exception Handling to Form Manipulation CWE-636 9.8 Critical 2024-05-02
CVE-2023-51411 WordPress Frontend Admin by DynamiApps Plugin <= 3.18.3 is vulnerable to Arbitrary File Upload CWE-434 10.0 Critical 2023-12-29

All 29 known CVE vulnerabilities affecting Frontend Admin by DynamiApps with full Chinese analysis, references, and POCs where available.