CVE-2026-13609: Frontend Admin by DynamiApps < 3.29.9 - Unauthenticated Stored Cross-Site Scripting via Form Field
The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauthenticated visitor is therefore stored as a live tag and later output without escaping on the Frontend Admin by DynamiApps WordPress plugin before 3.29.9's front-end display surfaces, resulting in stored cross-site scripting that executes in the browser of any user, including an administrator, who views a page displaying the submitted value.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13609?
CVE-2026-13609 has a risk score of 62, indicating a moderate severity vulnerability.
How do I fix CVE-2026-13609?
To fix CVE-2026-13609, update the DynamiApps Frontend Admin plugin to version 3.29.9 or later.
What type of vulnerability is CVE-2026-13609?
CVE-2026-13609 is classified as an unauthenticated stored cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2026-13609?
Any website using versions of the DynamiApps Frontend Admin plugin prior to 3.29.9 is at risk of CVE-2026-13609.
What is the impact of CVE-2026-13609?
CVE-2026-13609 allows attackers to store and execute malicious scripts on affected websites, potentially compromising user data.