CVE-2026-18432Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the check to be skipped entirely when `$user_id` is a non-numeric string — a condition that can be induced by passing a crafted value such as `1one` through the unvalidated `item_id` parameter of the unauthenticated `wp_ajax_nopriv_frontend_admin/forms/change_form` AJAX endpoint. This makes it possible for attackers to escalate privileges to administrator by obtaining a server-signed `_acf_objects` payload carrying the non-numeric user ID, which WordPress subsequently coerces to integer 1 (the default administrator), allowing the attacker to overwrite that account's password or email address. Exploitation by unauthenticated users requires a public-facing frontend user form to be configured; in all other cases a subscriber-level account is sufficient.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-08-16); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-16: 3Mentions · 2026-08-17: 1Technical Details · 2026-08-16: 308-1608-17
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-163
Disclosure2General1
2026-08-171
Disclosure1
Full discourse4 posts
  • HOL@HashgraphOnline
    Disclosure

    BREAKING: CVE-2026-18432 is a CVSS 9.8 flaw in Frontend Admin by DynamiApps (WordPress, 9,000+ installs). A crafted non-numeric item_id can skip the plugin's edit_user authorization check, then get coerced back to user ID 1 later in the flow. On exposed frontend user forms, that can mean unauthenticated administrator takeover. https://hol.org/blog/cve-2026-18432-frontend-admin-wordpress-unauth-admin-takeover

    Post summary

    The post announces CVE-2026-18432, detailing a severe RCE/authorization bypass flaw in Frontend Admin that permits unauthenticated administrator takeover, but it provides no PoC, exploit code, or patches.

    10000449
    15.9K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en complementos de WordPress ❗ CVE-2026-18432 ❗ CVE-2026-17123 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-wordpress-3/ https://t.co/pIgh5axTZu

    Post summary

    The post announces two WordPress plugin vulnerabilities (CVE-2026-18432 and CVE-2026-17123) and links to a CERT page for more information.

    00000212
    6.7K followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🔐🚨 Frontend Admin WordPress Plugin — CVSS 9.8 CRITICAL CVE-2026-18432: Unauthenticated privilege escalation via ActionUser hook → Full admin takeover → https://threataft.com/articles/frontend-admin-dynamiapps-cve-2026-18432 #cybersecurity #infosec #WordPress #PluginSecurity #CVSS9 #CVE #ThreatIntel

    Post summary

    The post announces CVE‑2026‑18432, highlighting its critical severity and privilege‑escalation flaw, but does not provide exploit code, active attack evidence, or remediation guidance.

    0000054
    36 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-18432 Privilege Escalation in Frontend Admin by DynamiApps WordPress Plugin Up To 3.29.9 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-18432

    Post summary

    The post lists a CVE with a brief description of privilege escalation in a WordPress plugin, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    00000120
    4.1K followersView on X

Explore more