CVE-2026-66470 HIGH

CVE-2026-66470: WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Broken Access Control vulnerability

Vendor Shabti Kaplan
Product Frontend Admin by DynamiApps
Weakness CWE-862 · Missing authorization
Published August 6, 2026
Last update August 6, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

What the vulnerability does

01Description

Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.

Explanation of Vulnerability in Simple Terms

02Summary

Frontend Admin by DynamiApps versions up to 3.29.10 lack proper authorization checks, allowing authenticated users to modify site content and disrupt service availability. An attacker with low-level access can bypass intended restrictions to alter data or cause the site to become unavailable. No confidentiality breach occurs, but integrity and availability are at risk.

What an attacker can do

03Attacker Capabilities

Modify site content and cause service disruption without proper authorization.

Potential impact on your site

04Site Impact

Authenticated users can alter content and crash the site; you may lose data integrity and uptime.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege user account on the site.

Key dates

06Disclosure timeline

August 6, 2026 CVE published
August 6, 2026 Record updated

Related vulnerabilities

08Related CVE