
BREAKING: CVE-2026-18432 is a CVSS 9.8 flaw in Frontend Admin by DynamiApps (WordPress, 9,000+ installs). A crafted non-numeric item_id can skip the plugin's edit_user authorization check, then get coerced back to user ID 1 later in the flow. On exposed frontend user forms, that can mean unauthenticated administrator takeover. https://hol.org/blog/cve-2026-18432-frontend-admin-wordpress-unauth-admin-takeover
Post summary
The post announces CVE-2026-18432, detailing a severe RCE/authorization bypass flaw in Frontend Admin that permits unauthenticated administrator takeover, but it provides no PoC, exploit code, or patches.



