Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 06 Sep 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shabti
Shabti frontend Admin By Dynamapps Wordpress Wordpress wordpress |
|
| Vendors & Products |
Shabti
Shabti frontend Admin By Dynamapps Wordpress Wordpress wordpress |
Sun, 06 Sep 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check, and ActionPost::conditions_logic() short-circuiting its current_user_can('edit_post') authorization gate whenever the post ID is non-numeric — such as the string user_1 — allowing unauthenticated form submissions to be routed to arbitrary user records without restriction. This makes it possible for unauthenticated attackers to overwrite any user's registered email address, including an administrator's, and then leverage WordPress's native password-reset flow to fully take over the targeted account. | |
| Title | Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_objects' Object Identifier | |
| Weaknesses | CWE-287 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-09-06T02:26:52.017Z
Reserved: 2026-08-18T10:01:34.135Z
Link: CVE-2026-75816
No data.
Status : Received
Published: 2026-09-06T03:17:16.607
Modified: 2026-09-06T03:17:16.607
Link: CVE-2026-75816
No data.
OpenCVE Enrichment
Updated: 2026-09-06T03:30:05Z