The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated users with low privileges (such as Subscribers) to create, rename, and delete arbitrary taxonomy terms.
We have discovered 1,458 live websites that are affected by CVE-2026-11867.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,458 live websites (100% of Acf Frontend Form Element install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 69 versions ( 96% of all versions) |
| 410 websites | |
| 150 websites | |
| 116 websites | |
| 71 websites | |
| 61 websites | |
| 55 websites | |
| 45 websites | |
| 44 websites | |
| 37 websites | |
| 36 websites |
| .com | 495 websites |
| .org | 139 websites |
| .de | 71 websites |
| .fr | 62 websites |
| .net | 40 websites |
| .com.br | 37 websites |
| .co.uk | 36 websites |
| .ch | 33 websites |
| .nl | 30 websites |
| .it | 29 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *************.jp | **,*** | ||
| *************.cu | **,*** | ||
| *******.com | **,*** | ||
| *************.**.jp | ***,*** | ||
| ********.org | ***,*** | ||
| ********.**.jp | ***,*** | ||
| **********.jp | ***,*** | ||
| *******.**.jp | ***,*** | ||
| *********.**.jp | ***,*** | ||
| **************.org | ***,*** |
FAQ