August 29, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-81346NVD

Vulnerability Summary

The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans.
Severity Level
UNKNOWN
Published Date
Aug 29, 2026
Last Modified
Aug 29, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
N/A