CVE-2026-18432: CWE-269 Improper Privilege Management in shabti Frontend Admin by DynamiApps
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the check to be skipped entirely when `$user_id` is a non-numeric string — a condition that can be induced by passing a crafted value such as `1one` through the unvalidated `item_id` parameter of the unauthenticated `wp_ajax_nopriv_frontend_admin/forms/change_form` AJAX endpoint. This makes it possible for attackers to escalate privileges to administrator by obtaining a server-signed `_acf_objects` payload carrying the non-numeric user ID, which WordPress subsequently coerces to integer 1 (the default administrator), allowing the attacker to overwrite that account's password or email address. Exploitation by unauthenticated users requires a public-facing frontend user form to be configured; in all other cases a subscriber-level account is sufficient.
AI Analysis
Technical Summary
The Frontend Admin by DynamiApps WordPress plugin (versions <=3.29.9) contains a privilege escalation vulnerability (CWE-269) due to improper privilege management. The function ActionUser::conditions_logic() gates the authorization check current_user_can('edit_user', $user_id) behind an is_numeric() test. When a non-numeric string is passed as $user_id (e.g., '1one'), the authorization check is skipped. This can be triggered via the unvalidated item_id parameter in the unauthenticated wp_ajax_nopriv_frontend_admin/forms/change_form AJAX endpoint. An attacker can obtain a server-signed _acf_objects payload carrying the crafted user ID, which WordPress coerces to integer 1 (the default administrator user ID), enabling the attacker to overwrite the administrator account's password or email address. Exploitation requires a public-facing frontend user form or subscriber-level access otherwise.
Potential Impact
Successful exploitation allows unauthenticated attackers (if a public frontend user form is configured) or subscriber-level users to escalate privileges to administrator. This enables full control over the WordPress site by overwriting the administrator account's password or email, leading to complete compromise of confidentiality, integrity, and availability of the affected system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict or disable public-facing frontend user forms if possible and monitor for unusual activity related to the affected AJAX endpoint. Avoid exposing the vulnerable plugin or upgrade promptly once a patch is released.
CVE-2026-18432: CWE-269 Improper Privilege Management in shabti Frontend Admin by DynamiApps
Description
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the check to be skipped entirely when `$user_id` is a non-numeric string — a condition that can be induced by passing a crafted value such as `1one` through the unvalidated `item_id` parameter of the unauthenticated `wp_ajax_nopriv_frontend_admin/forms/change_form` AJAX endpoint. This makes it possible for attackers to escalate privileges to administrator by obtaining a server-signed `_acf_objects` payload carrying the non-numeric user ID, which WordPress subsequently coerces to integer 1 (the default administrator), allowing the attacker to overwrite that account's password or email address. Exploitation by unauthenticated users requires a public-facing frontend user form to be configured; in all other cases a subscriber-level account is sufficient.
CVSS v3.1
Score 9.8critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Frontend Admin by DynamiApps WordPress plugin (versions <=3.29.9) contains a privilege escalation vulnerability (CWE-269) due to improper privilege management. The function ActionUser::conditions_logic() gates the authorization check current_user_can('edit_user', $user_id) behind an is_numeric() test. When a non-numeric string is passed as $user_id (e.g., '1one'), the authorization check is skipped. This can be triggered via the unvalidated item_id parameter in the unauthenticated wp_ajax_nopriv_frontend_admin/forms/change_form AJAX endpoint. An attacker can obtain a server-signed _acf_objects payload carrying the crafted user ID, which WordPress coerces to integer 1 (the default administrator user ID), enabling the attacker to overwrite the administrator account's password or email address. Exploitation requires a public-facing frontend user form or subscriber-level access otherwise.
Potential Impact
Successful exploitation allows unauthenticated attackers (if a public frontend user form is configured) or subscriber-level users to escalate privileges to administrator. This enables full control over the WordPress site by overwriting the administrator account's password or email, leading to complete compromise of confidentiality, integrity, and availability of the affected system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict or disable public-facing frontend user forms if possible and monitor for unusual activity related to the affected AJAX endpoint. Avoid exposing the vulnerable plugin or upgrade promptly once a patch is released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-07-30T20:03:25.244Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a813f8bbf8831d539784d04
Added to database: 08/16/2026, 04:41:47 UTC
Last enriched: 08/23/2026, 13:01:58 UTC
Last updated: 09/06/2026, 13:55:30 UTC
Views: 116
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.