VYPR

Frontend Admin By Dynamiapps

by WordPress

CVEs (25)

  • CVE-2026-81347MedSep 4, 2026
    risk 0.38cvss 5.9epss 0.00

    The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files outside the intended directory, including…

  • CVE-2024-11722MedDec 21, 2024
    risk 0.38cvss 5.9epss 0.01

    The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.25.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…

  • CVE-2026-10039MedMay 29, 2026
    risk 0.32cvss 4.9epss 0.00

    The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, 3.28.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…

  • CVE-2026-81346MedAug 29, 2026
    risk 0.28cvss 4.3epss 0.00

    The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans.

  • CVE-2026-11867MedJul 30, 2026
    risk 0.00cvss 6.5epss 0.00

    The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated users with low privileges (such as Subscribers) to create, rename, and delete arbitrary…

Page 2 of 2