CVE-2025-26987: WordPress Frontend Admin by DynamiApps plugin <= 3.25.17 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps acf-frontend-form-element allows Reflected XSS.This issue affects Frontend Admin by DynamiApps: from n/a through <= 3.25.17.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26987?
CVE-2025-26987 is classified as a medium severity vulnerability due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-26987?
To fix CVE-2025-26987, update the Frontend Admin by DynamiApps to version 3.25.18 or later.
What type of vulnerability is CVE-2025-26987?
CVE-2025-26987 is a reflected cross-site scripting (XSS) vulnerability.
Which versions of Frontend Admin by DynamiApps are affected by CVE-2025-26987?
CVE-2025-26987 affects Frontend Admin by DynamiApps from n/a up to version 3.25.17.
What impact does CVE-2025-26987 have on users?
CVE-2025-26987 can allow attackers to execute scripts in the context of users' browsers, potentially leading to data theft or session hijacking.