THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-75816 (CRITICAL 9.8) — The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check, and ActionPost::conditions_logic

[NVD] CVE-2026-75816 (CRITICAL 9.8) — The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check, and ActionPost::conditions_logic

mednvdPublished 2026-09-06

CVE-2026-75816 CVSS: 9.8 CRITICAL Published: 2026-09-06T03:17:16.607

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check, and ActionPost::conditions_logic() short-circuiting its current_user_can('edit_pos

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-75816