Description
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the check to be skipped entirely when `$user_id` is a non-numeric string — a condition that can be induced by passing a crafted value such as `1one` through the unvalidated `item_id` parameter of the unauthenticated `wp_ajax_nopriv_frontend_admin/forms/change_form` AJAX endpoint. This makes it possible for attackers to escalate privileges to administrator by obtaining a server-signed `_acf_objects` payload carrying the non-numeric user ID, which WordPress subsequently coerces to integer 1 (the default administrator), allowing the attacker to overwrite that account's password or email address. Exploitation by unauthenticated users requires a public-facing frontend user form to be configured; in all other cases a subscriber-level account is sufficient.
Published: 2026-08-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.3/main/frontend/forms/actions/user.php#L565 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.3/main/frontend/forms/actions/user.php#L680 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.3/main/frontend/forms/classes/display.php#L1654 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.3/main/frontend/forms/classes/display.php#L1953 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.3/main/frontend/forms/classes/display.php#L37 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.9/main/frontend/forms/actions/user.php#L565 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.9/main/frontend/forms/actions/user.php#L680 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.9/main/frontend/forms/classes/display.php#L1654 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.9/main/frontend/forms/classes/display.php#L1953 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.9/main/frontend/forms/classes/display.php#L37 cve-icon cve-icon
https://plugins.trac.wordpress.org/changeset?reponame=&old=3633030%40acf-frontend-form-element&new=3633030%40acf-frontend-form-element cve-icon cve-icon
https://www.wordfence.com/threat-intel/vulnerabilities/id/01404fad-7b5a-485a-b557-c608fe25e6c9?source=cve cve-icon cve-icon
History

Sun, 16 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Shabti
Shabti frontend Admin By Dynamapps
Wordpress
Wordpress wordpress
Vendors & Products Shabti
Shabti frontend Admin By Dynamapps
Wordpress
Wordpress wordpress

Sun, 16 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Description The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the check to be skipped entirely when `$user_id` is a non-numeric string — a condition that can be induced by passing a crafted value such as `1one` through the unvalidated `item_id` parameter of the unauthenticated `wp_ajax_nopriv_frontend_admin/forms/change_form` AJAX endpoint. This makes it possible for attackers to escalate privileges to administrator by obtaining a server-signed `_acf_objects` payload carrying the non-numeric user ID, which WordPress subsequently coerces to integer 1 (the default administrator), allowing the attacker to overwrite that account's password or email address. Exploitation by unauthenticated users requires a public-facing frontend user form to be configured; in all other cases a subscriber-level account is sufficient.
Title Frontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_id' Parameter
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Shabti Frontend Admin By Dynamapps
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-16T04:24:49.468Z

Reserved: 2026-07-30T20:03:25.244Z

Link: CVE-2026-18432

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-16T05:16:48.307

Modified: 2026-08-16T05:16:48.307

Link: CVE-2026-18432

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-16T10:15:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management