A critical unauthenticated privilege-escalation flaw, CVE-2026-75816 (CVSS 9.8), affects the Frontend Admin by DynamiApps WordPress plugin, distributed under the acf-frontend-form-element slug. The vulnerability affects versions through 3.29.12 and stems from missing capability checks and an authorization bypass when non-numeric user or post identifiers are supplied.
An unauthenticated attacker can alter arbitrary users’ email addresses, then invoke WordPress’s password-reset process to seize an administrator account and fully compromise the affected site. DynamiApps remediated the issue in version 3.29.13; administrators should update immediately and review user email changes and password-reset activity. No active exploitation was reported at publication.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Frontend Admin version 3.29.13 introduced improved permission checks to address CVE-2026-75816. The source reported no known active exploitation at the time of publication.
CVE-2026-75816 was identified in Frontend Admin by DynamiApps versions through 3.29.12. The missing capability checks and authorization bypass can let an unauthenticated attacker alter an administrator's email address and use the WordPress password-reset flow to take over the account.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.