The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the check to be skipped entirely when `$user_id` is a non-numeric string — a condition that can be induced by passing a crafted value such as `1one` through the unvalidated `item_id` parameter of the unauthenticated `wp_ajax_nopriv_frontend_admin/forms/change_form` AJAX endpoint. This makes it possible for attackers to escalate privileges to administrator by obtaining a server-signed `_acf_objects` payload carrying the non-numeric user ID, which WordPress subsequently coerces to integer 1 (the default administrator), allowing the attacker to overwrite that account's password or email address. Exploitation by unauthenticated users requires a public-facing frontend user form to be configured; in all other cases a subscriber-level account is sufficient.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.3/main/frontend/forms/actions/user.php#L565 cve-icon
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.3/main/frontend/forms/actions/user.php#L680 cve-icon
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.3/main/frontend/forms/classes/display.php#L1654 cve-icon
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.3/main/frontend/forms/classes/display.php#L1953 cve-icon
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.3/main/frontend/forms/classes/display.php#L37 cve-icon
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.9/main/frontend/forms/actions/user.php#L565 cve-icon
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.9/main/frontend/forms/actions/user.php#L680 cve-icon
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.9/main/frontend/forms/classes/display.php#L1654 cve-icon
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.9/main/frontend/forms/classes/display.php#L1953 cve-icon
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.9/main/frontend/forms/classes/display.php#L37 cve-icon
https://plugins.trac.wordpress.org/changeset?reponame=&old=3633030%40acf-frontend-form-element&new=3633030%40acf-frontend-form-element cve-icon
https://www.wordfence.com/threat-intel/vulnerabilities/id/01404fad-7b5a-485a-b557-c608fe25e6c9?source=cve cve-icon
History

Sun, 16 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Description The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the check to be skipped entirely when `$user_id` is a non-numeric string — a condition that can be induced by passing a crafted value such as `1one` through the unvalidated `item_id` parameter of the unauthenticated `wp_ajax_nopriv_frontend_admin/forms/change_form` AJAX endpoint. This makes it possible for attackers to escalate privileges to administrator by obtaining a server-signed `_acf_objects` payload carrying the non-numeric user ID, which WordPress subsequently coerces to integer 1 (the default administrator), allowing the attacker to overwrite that account's password or email address. Exploitation by unauthenticated users requires a public-facing frontend user form to be configured; in all other cases a subscriber-level account is sufficient.
Title Frontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_id' Parameter
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-16T04:24:49.468Z

Reserved: 2026-07-30T20:03:25.244Z

Link: CVE-2026-18432

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses