CVE-2026-11867: Frontend Admin by DynamiApps < 3.29.7 - Subscriber+ Taxonomy Term Creation/Modification/Deletion via Missing Authorization
The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated users with low privileges (such as Subscribers) to create, rename, and delete arbitrary taxonomy terms.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11867?
CVE-2026-11867 has a medium severity rating of 6.5 according to CVSS 3.1.
How do I fix CVE-2026-11867?
You can fix CVE-2026-11867 by updating the Frontend Admin by DynamiApps plugin to version 3.29.7 or later.
What systems are affected by CVE-2026-11867?
CVE-2026-11867 affects versions of the Frontend Admin by DynamiApps plugin prior to 3.29.7.
What type of vulnerability is CVE-2026-11867?
CVE-2026-11867 is a missing authorization vulnerability that allows low-privileged authenticated users to manipulate taxonomy terms.
Who can exploit CVE-2026-11867?
Authenticated users with low privileges, such as Subscribers, can exploit CVE-2026-11867 to create, modify, or delete taxonomy terms.