Frontend Admin by DynamiApps

Frontend Admin by DynamiApps has 30 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2026; all 30 are fixed as of September 2026. Their average CVSS score is 7.5, and the most serious one scores 9.8 out of 10. Severity breakdown: 8 critical and 10 high. 2026 was the busiest year with 19 disclosures.

The most common weakness is Cross-Site Scripting, behind 7 of the records (23%). Other recurring categories include Missing Authorization, Improper Privilege Management.

Every one of the 30 issues recorded for Frontend Admin by DynamiApps has a vendor fix available, so running the current release closes all known holes.

23 independent researchers contributed these findings, most of them (3) reported by Max Boll (_b0lli). Frontend Admin by DynamiApps is installed on roughly 8,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.0.

01234567891019.09.2019Today04.03.20226.3Freemius SDK <= 2.4.2 - Missing Authorization Checks CVSS 6.3 · 04.03.202218.07.20236.1Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get CVSS 6.1 · 18.07.202327.12.20239.8Frontend Admin by DynamiApps Plugin <= 3.18.3 - Unauthenticated Arbitrary File Upload CVSS 9.8 · 27.12.202318.04.20249.8Frontend Admin by DynamiApps <= 3.19.4 - Improper Missing Encryption Exception Handling to Form Manipulation CVSS 9.8 · 18.04.202413.12.20247.2Frontend Admin by DynamiApps <= 3.24.5 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 13.12.20248.1Frontend Admin by DynamiApps <= 3.24.5 - Unauthenticated Privilege Escalation CVSS 8.1 · 13.12.202420.12.20245.9Frontend Admin by DynamiApps <= 3.25.1 - Unauthenticated SQL Injection CVSS 5.9 · 20.12.202423.02.20256.1Frontend Admin by DynamiApps <= 3.25.17 - Reflected Cross-Site Scripting CVSS 6.1 · 23.02.202526.06.20256.5Frontend Admin by DynamiApps <= 3.28.7 - Authenticated (Editor+) Arbitrary File Deletion CVSS 6.5 · 26.06.202512.08.20256.5Frontend Admin by DynamiApps <= 3.28.3 - Authenticated (Subscriber+) SQL Injection CVSS 6.5 · 12.08.202503.12.20259.8Frontend Admin by DynamiApps <= 3.28.20 - Unauthenticated Arbitrary Options Update CVSS 9.8 · 03.12.202508.01.20269.8Frontend Admin by DynamiApps <= 3.28.29 - Unauthenticated Privilege Escalation to Administrator via Role Form Field CVSS 9.8 · 08.01.20269.1Frontend Admin by DynamiApps <= 3.28.25 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via 'delete post' Form Element CVSS 9.1 · 08.01.20267.2Frontend Admin by DynamiApps <= 3.28.23 - Unauthenticated Stored Cross-Site Scripting via 'update_field' CVSS 7.2 · 08.01.202625.03.20267.2Frontend Admin by DynamiApps <= 3.28.31 - Authenticated (Editor+) PHP Object Injection via 'post_content' of Admin Form Posts CVSS 7.2 · 25.03.202614.05.20268.8Frontend Admin by DynamiApps <= 3.28.36 - Unauthenticated Privilege Escalation via Edit User Form CVSS 8.8 · 14.05.202627.05.20268.8Frontend Admin by DynamiApps <= 3.29.2 - Unauthenticated Privilege Escalation via Form Configuration Injection CVSS 8.8 · 27.05.20268.8Frontend Admin by DynamiApps <= 3.29.2 - Missing Authorization to Authenticated (Subscriber+) Account Takeover via 'user_id' URL Query Parameter CVSS 8.8 · 27.05.202628.05.20264.9Frontend Admin by DynamiApps <= 3.28.28 - Authenticated (Administrator+) SQL Injection via 'order' Parameter CVSS 4.9 · 28.05.202616.07.20267.2Frontend Admin by DynamiApps <= 3.29.8 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 16.07.202605.08.20264.3Frontend Admin by DynamiApps < 3.29.7 - Missing Authorization CVSS 4.3 · 05.08.20264.3Frontend Admin by DynamiApps <= 3.29.10 - Missing Authorization CVSS 4.3 · 05.08.20269.8Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Privilege Escalation CVSS 9.8 · 05.08.202611.08.20268.8Frontend Admin by DynamiApps <= 3.29.9 - Authenticated (Subscriber+) Arbitrary Password Reset via Encrypted Object Token CVSS 8.8 · 11.08.202615.08.20269.8Frontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_id' Parameter CVSS 9.8 · 15.08.202618.08.20266.4Frontend Admin by DynamiApps <= 3.29.10 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 18.08.202627.08.20264.3Frontend Admin by DynamiApps < 3.29.11 - Authenticated (Subscriber+) Membership Plan Deletion CVSS 4.3 · 27.08.202631.08.20267.5Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Arbitrary File Deletion via Path Traversal via custom_directory_name Merge Tag CVSS 7.5 · 31.08.20266.4Frontend Admin by DynamiApps <= 3.29.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Shortcode Attribute CVSS 6.4 · 31.08.202605.09.20269.8Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_objects' Object Identifier CVSS 9.8 · 05.09.2026

Strategic Overview

Avg CVSSHigh
7.5/ 10
Patch Coverage100%
Open

0

Fixed

30

Get automatic notifications for all Frontend Admin by DynamiApps vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2026-75816

Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_objects' Object Identifier

Read the full analysis

Vulnerability Records

30 records
2026-09-05 13:59CVE-2026-75816
9.8
Critical
thevietroninYes
2026-08-31 15:50CVE-2026-12747
6.4
Medium
Wordfence PRISMYes
2026-08-31 15:49CVE-2026-19952
7.5
High
nudienYes
2026-08-27 00:00CVE-2026-81346
4.3
Medium
Sai Praneeth KotiYes
2026-08-18 00:00CVE-2026-66638
6.4
Medium
Ananda DhakalYes
2026-08-15 15:30CVE-2026-18432
9.8
Critical
밥김국Yes
2026-08-11 07:56CVE-2026-15606
8.8
High
darooYes
2026-08-05 00:00CVE-2026-11867
4.3
Medium
Meher Sudhakar AbbireddiYes
2026-08-05 00:00CVE-2026-66470
4.3
Medium
okndjoYes
2026-08-05 00:00CVE-2026-66662
9.8
Critical
Doan Dinh VanYes
Showing 1–10 of 30 reports
Frontend Admin by DynamiApps banner
Latestv3.29.13

Frontend Admin by DynamiApps

Shabti Kaplan

Author

Shabti Kaplan

4.5(159)
90/100
Last Updated
2026-08-25 (19d ago)
Active Installs
8,000+
Downloads
983,887
Requires WP
4.6+
Requires PHP
5.6.0+
Tested up to
WP 7.0.0
Created
2019-09-19 (7y ago)

Add and edit posts, pages, users, terms, ACF fields and more all from the frontend. (Previously called ACF Frontend) This awesome plugin allows you to easily display frontend admin forms on your site so your clients can easily edit content by themselves from the frontend. You can create awesome forms with our form builder to allow users to save custom meta data to pages, posts, users, and more. Then use our Gutenberg block or shortcode to easily display these forms for your users. So, what can this plugin do for you? FREE Features No Coding Required Give the end user the best content managment experience without having to know code. It’s all ready to go right here. Display Post Data Use [frontend_admin field=field_key] to display any field value effortlessly Edit Posts Let your users edit posts from the frontend of their site without having to access the WordPress dashboard. Add Posts Let your users publish new posts from the frontend using the “new post” form Delete Posts Let your users delete or trash posts from the frontend using the “trash button” form Edit User Profile Allow users to edit their user data easily from the frontend. User Registration Form Allow new users to register to your site with a built in user registration form! You can even hide the WordPress dashboard from these new users. Hide Admin Area Pick and chose which users have acess to the WordPress admin area. Configure Permissions Choose who sees your form based on user role or by specific users. Modal Popup Display the form in a modal window that opens when clicking a button so that it won’t take up any space on your pages. PRO Features Edit Global Options If you have global data – like header and footer data – you can create an options page using ACF and let your users edit from the frontend. Limit Submits Prevent all or specific users from submitting the form more than a number of times. Send Emails Set emails to be sent and map the ACF form data to display in the email fields such as the email address, the from address, subject, and message. Style Tab Use Elementor to style the form and as well the buttons. Multi Step Forms Make your forms more engaging by adding multiple steps. Stripe and Paypal Accept payments through Stripe or Paypal upon form submission. Woocommerce Intergration Easily add Woocomerce products from the frontend. Purchase your copy here at the official website: Frontend Admin website Intergrations Page Builders Frontend Admin works with all WordPress page builders, including: Elementor Bricks Builder Spectra Website Builder Divi Builder Beaver Builder Thrive Architect Gutenberg Oxygen Builder And others Other Plugins Frontend Admin has built-in integrations with very popular plugins, such as: WooCommmerce Easy Digital Downloads SureCart Advanced Custom Fields Pods And more Useful Links Appreciate what we’re doing? Want to stay updated with new features? Give us a like and follow us on our facebook page: Frontend Admin Facebook page The Pro version has even more cool features. Check it out at the official website: DynamiApps website Check out our other plugin, which let’s you dynamically query your posts more easily: Advanced Post Queries for Elementor Tutorials = The New Post Form Block = https://www.youtube.com/watch?v=SIwiWvPqd8Q = Paul from WPTuts shows how to build a fully functional front-end dashboard in WordPress using the free Front-End Admin plugin and Bricks Builder. https://www.youtube.com/watch?v=O0TYRap8U24 Paul from WP Tuts shows how to use Frontend Admin to create a frontend dashboard Bjorn from WPLearningLab shows how to create a WordPress Client Portal Integrating Bricks Builder with Frontend Admin Frontend Forms in Elementor Pro Off Canvas Widget Frontend Admin’s Elementor Nestable Forms Widget on WordPress Enable Users To Add Content From The Front End Without Logging Into WordPress Using Frontend Admin WordPress Frontend Edits and Updates Using Frontend Admin Installating Frontend Admin How to create a form for frontend data submission

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C