CVE-2026-81346 PUBLISHED

Frontend Admin by DynamiApps < 3.29.11 - Subscriber+ Arbitrary Membership Plan Deletion

Assigner: WPScan
Reserved: 26.08.2026 Published: 29.08.2026 Updated: 29.08.2026

The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans.

Product Status

Vendor Unknown
Product Frontend Admin by DynamiApps
Versions Default: unaffected
  • affected from 0 to 3.29.11 (excl.)

Credits

  • Sai Praneeth Koti finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE