Extension WordPress

Vulnérabilités Frontend Admin by DynamiApps

Cette page rassemble les failles publiées pour Frontend Admin by DynamiApps, leurs plages de versions affectées et les correctifs signalés dans la base locale.

28Vulnérabilités
7Critiques
27Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Frontend Admin by DynamiApps

28 fiches

CVE-2026-12747 Moyenne · 6,4
Frontend Admin by DynamiApps

Frontend Admin by DynamiApps <= 3.29.11 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Shortcode Attribute

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortcode Attribute in all versions up to, and including, 3.29.11 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-3.29.11

Correctif

3.29.12

Publication

31/08/2026

CVE-2026-19952 Élevée · 7,5
Frontend Admin by DynamiApps

Frontend Admin by DynamiApps <= 3.29.12 – Unauthenticated Arbitrary File Deletion via Path Traversal via custom_directory_name Merge Tag

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and including, 3.29.12. This makes it possible for unauthenticated…

Versions affectées

*-3.29.12

Correctif

3.29.13

Publication

31/08/2026

CVE-2026-66638 Moyenne · 6,4
Frontend Admin by DynamiApps

Frontend Admin by DynamiApps <= 3.29.10 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.29.10. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-3.29.10

Correctif

3.29.11

Publication

18/08/2026

CVE-2026-18432 Critique · 9,8
Frontend Admin by DynamiApps

Frontend Admin by DynamiApps <= 3.29.9 – Unauthenticated Privilege Escalation via 'item_id' Parameter

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the…

Versions affectées

*-3.29.9

Correctif

3.29.10

Publication

15/08/2026

CVE-2026-15606 Élevée · 8,8
Frontend Admin by DynamiApps

Frontend Admin by DynamiApps <= 3.29.9 – Authenticated (Subscriber+) Arbitrary Password Reset via Encrypted Object Token

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due to the plugin not properly verifying that a user is authorized to perform an…

Versions affectées

*-3.29.9

Correctif

3.29.10

Publication

11/08/2026

CVE-2026-13609 Élevée · 7,2
Frontend Admin by DynamiApps

Frontend Admin by DynamiApps <= 3.29.8 – Unauthenticated Stored Cross-Site Scripting

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.29.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

Versions affectées

*-3.29.8

Correctif

3.29.9

Publication

16/07/2026

CVE-2026-10039 Moyenne · 4,9
Frontend Admin by DynamiApps

Frontend Admin by DynamiApps <= 3.28.28 – Authenticated (Administrator+) SQL Injection via 'order' Parameter

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, 3.28.28 due to insufficient escaping on the user supplied parameter and lack of…

Versions affectées

*-3.28.8

Correctif

3.28.29

Publication

28/05/2026

CVE-2026-7802 Élevée · 8,8
Frontend Admin by DynamiApps

Frontend Admin by DynamiApps <= 3.29.2 – Missing Authorization to Authenticated (Subscriber+) Account Takeover via 'user_id' URL Query Parameter

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.2. This is due to the plugin not properly verifying that a user is authorized to perform an…

Versions affectées

*-3.29.2

Correctif

3.29.3

Publication

27/05/2026

CVE-2026-6226 Élevée · 8,8
Frontend Admin by DynamiApps

Frontend Admin by DynamiApps <= 3.29.2 – Unauthenticated Privilege Escalation via Form Configuration Injection

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to and including 3.29.2. This is due to insecure form submission handling that accepts arbitrary form definitions from user input instead…

Versions affectées

*-3.29.2

Correctif

3.29.3

Publication

27/05/2026

CVE-2026-6228 Élevée · 8,8
Frontend Admin by DynamiApps

Frontend Admin by DynamiApps <= 3.28.36 – Unauthenticated Privilege Escalation via Edit User Form

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 3.28.36. This is due to insufficient authorization checks in the role field update mechanism combined with overly permissive capabilities…

Versions affectées

*-3.28.36

Correctif

3.29.1

Publication

14/05/2026

CVE-2026-3328 Élevée · 7,2
Frontend Admin by DynamiApps

Frontend Admin by DynamiApps <= 3.28.31 – Authenticated (Editor+) PHP Object Injection via 'post_content' of Admin Form Posts

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to PHP Object Injection via deserialization of the 'post_content' of admin_form posts in all versions up to, and including, 3.28.31. This is due to the use of WordPress's…

Versions affectées

*-3.28.31

Correctif

3.28.32

Publication

25/03/2026

CVE-2025-14937 Élevée · 7,2
Frontend Admin by DynamiApps

Frontend Admin by DynamiApps <= 3.28.23 – Unauthenticated Stored Cross-Site Scripting via 'update_field'

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acff' parameter in the 'frontend_admin/forms/update_field' AJAX action in all versions up to, and including, 3.28.23 due to insufficient input sanitization and output…

Versions affectées

*-3.28.23

Correctif

3.28.24

Publication

08/01/2026

CVE-2025-14741 Critique · 9,1
Frontend Admin by DynamiApps

Frontend Admin by DynamiApps <= 3.28.25 – Missing Authorization to Unauthenticated Arbitrary Data Deletion via 'delete post' Form Element

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modification and deletion due to a missing capability check on the 'delete_object' function in all versions up to, and including, 3.28.25. This…

Versions affectées

*-3.28.25

Correctif

3.28.26

Publication

08/01/2026

CVE-2025-14736 Critique · 9,8
Frontend Admin by DynamiApps

Frontend Admin by DynamiApps <= 3.28.29 – Unauthenticated Privilege Escalation to Administrator via Role Form Field

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.29. This is due to insufficient validation of user-supplied role values in the 'validate_value', 'pre_update_value', and 'get_fields_display' functions.…

Versions affectées

*-3.28.29

Correctif

3.28.30

Publication

08/01/2026

CVE-2025-13342 Critique · 9,8
Frontend Admin by DynamiApps

Frontend Admin by DynamiApps <= 3.28.20 – Unauthenticated Arbitrary Options Update

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to, and including, 3.28.20. This is due to insufficient capability checks and input validation in the ActionOptions::run()…

Versions affectées

*-3.28.20

Correctif

3.28.21

Publication

03/12/2025

CVE-2025-49303 Moyenne · 6,5
Frontend Admin by DynamiApps

Frontend Admin by DynamiApps <= 3.28.7 – Authenticated (Editor+) Arbitrary File Deletion

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 3.28.7. This makes it possible for authenticated attackers, with Editor-level access…

Versions affectées

*-3.28.7

Correctif

3.28.8

Publication

26/06/2025

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités