Extension WordPress
Vulnérabilités Frontend Admin by DynamiApps
Cette page rassemble les failles publiées pour Frontend Admin by DynamiApps, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Frontend Admin by DynamiApps
28 fiches
Frontend Admin by DynamiApps <= 3.29.11 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Shortcode Attribute
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortcode Attribute in all versions up to, and including, 3.29.11 due to insufficient input sanitization and output escaping. This makes it possible…
*-3.29.11
3.29.12
31/08/2026
Frontend Admin by DynamiApps <= 3.29.12 – Unauthenticated Arbitrary File Deletion via Path Traversal via custom_directory_name Merge Tag
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and including, 3.29.12. This makes it possible for unauthenticated…
*-3.29.12
3.29.13
31/08/2026
Frontend Admin by DynamiApps <= 3.29.10 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.29.10. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-3.29.10
3.29.11
18/08/2026
Frontend Admin by DynamiApps <= 3.29.9 – Unauthenticated Privilege Escalation via 'item_id' Parameter
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the…
*-3.29.9
3.29.10
15/08/2026
Frontend Admin by DynamiApps <= 3.29.9 – Authenticated (Subscriber+) Arbitrary Password Reset via Encrypted Object Token
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due to the plugin not properly verifying that a user is authorized to perform an…
*-3.29.9
3.29.10
11/08/2026
Frontend Admin by DynamiApps <= 3.29.10 – Missing Authorization
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.29.10. This makes it possible for authenticated attackers, with subscriber-level…
*-3.29.10
3.29.11
05/08/2026
Frontend Admin by DynamiApps <= 3.29.10 – Unauthenticated Privilege Escalation
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.10. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
*-3.29.10
Non indiqué
05/08/2026
Frontend Admin by DynamiApps < 3.29.7 – Missing Authorization
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 3.29.7. This makes it possible for authenticated attackers, with subscriber-level access and…
[*, 3.29.7)
3.29.7
05/08/2026
Frontend Admin by DynamiApps <= 3.29.8 – Unauthenticated Stored Cross-Site Scripting
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.29.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
*-3.29.8
3.29.9
16/07/2026
Frontend Admin by DynamiApps <= 3.28.28 – Authenticated (Administrator+) SQL Injection via 'order' Parameter
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, 3.28.28 due to insufficient escaping on the user supplied parameter and lack of…
*-3.28.8
3.28.29
28/05/2026
Frontend Admin by DynamiApps <= 3.29.2 – Missing Authorization to Authenticated (Subscriber+) Account Takeover via 'user_id' URL Query Parameter
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.2. This is due to the plugin not properly verifying that a user is authorized to perform an…
*-3.29.2
3.29.3
27/05/2026
Frontend Admin by DynamiApps <= 3.29.2 – Unauthenticated Privilege Escalation via Form Configuration Injection
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to and including 3.29.2. This is due to insecure form submission handling that accepts arbitrary form definitions from user input instead…
*-3.29.2
3.29.3
27/05/2026
Frontend Admin by DynamiApps <= 3.28.36 – Unauthenticated Privilege Escalation via Edit User Form
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 3.28.36. This is due to insufficient authorization checks in the role field update mechanism combined with overly permissive capabilities…
*-3.28.36
3.29.1
14/05/2026
Frontend Admin by DynamiApps <= 3.28.31 – Authenticated (Editor+) PHP Object Injection via 'post_content' of Admin Form Posts
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to PHP Object Injection via deserialization of the 'post_content' of admin_form posts in all versions up to, and including, 3.28.31. This is due to the use of WordPress's…
*-3.28.31
3.28.32
25/03/2026
Frontend Admin by DynamiApps <= 3.28.23 – Unauthenticated Stored Cross-Site Scripting via 'update_field'
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acff' parameter in the 'frontend_admin/forms/update_field' AJAX action in all versions up to, and including, 3.28.23 due to insufficient input sanitization and output…
*-3.28.23
3.28.24
08/01/2026
Frontend Admin by DynamiApps <= 3.28.25 – Missing Authorization to Unauthenticated Arbitrary Data Deletion via 'delete post' Form Element
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modification and deletion due to a missing capability check on the 'delete_object' function in all versions up to, and including, 3.28.25. This…
*-3.28.25
3.28.26
08/01/2026
Frontend Admin by DynamiApps <= 3.28.29 – Unauthenticated Privilege Escalation to Administrator via Role Form Field
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.29. This is due to insufficient validation of user-supplied role values in the 'validate_value', 'pre_update_value', and 'get_fields_display' functions.…
*-3.28.29
3.28.30
08/01/2026
Frontend Admin by DynamiApps <= 3.28.20 – Unauthenticated Arbitrary Options Update
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to, and including, 3.28.20. This is due to insufficient capability checks and input validation in the ActionOptions::run()…
*-3.28.20
3.28.21
03/12/2025
Frontend Admin by DynamiApps <= 3.28.3 – Authenticated (Subscriber+) SQL Injection
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.28.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
*-3.28.3
3.28.5
12/08/2025
Frontend Admin by DynamiApps <= 3.28.7 – Authenticated (Editor+) Arbitrary File Deletion
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 3.28.7. This makes it possible for authenticated attackers, with Editor-level access…
*-3.28.7
3.28.8
26/06/2025
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.