The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the check to be skipped entirely when `$user_id` is a non-numeric string — a condition that can be induced by passing a crafted value such as `1one` through the unvalidated `item_id` parameter of the unauthenticated `wp_ajax_nopriv_frontend_admin/forms/change_form` AJAX endpoint. This makes it possible for attackers to escalate privileges to administrator by obtaining a server-signed `_acf_objects` payload carrying the non-numeric user ID, which WordPress subsequently coerces to integer 1 (the default administrator), allowing the attacker to overwrite that account's password or email address. Exploitation by unauthenticated users requires a public-facing frontend user form to be configured; in all other cases a subscriber-level account is sufficient.
We have discovered 1,436 live websites that are affected by CVE-2026-18432.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,436 live websites (100% of Acf Frontend Form Element install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 67 versions ( 94% of all versions) |
| 401 websites | |
| 148 websites | |
| 114 websites | |
| 70 websites | |
| 58 websites | |
| 57 websites | |
| 47 websites | |
| 42 websites | |
| 39 websites | |
| 38 websites |
| .com | 484 websites |
| .org | 141 websites |
| .de | 71 websites |
| .fr | 62 websites |
| .net | 40 websites |
| .co.uk | 37 websites |
| .ch | 35 websites |
| .com.br | 35 websites |
| .it | 31 websites |
| .nl | 31 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *************.jp | **,*** | ||
| *************.cu | **,*** | ||
| *************.**.jp | ***,*** | ||
| ********.org | ***,*** | ||
| ********.**.jp | ***,*** | ||
| **************.org | ***,*** | ||
| **********.jp | ***,*** | ||
| *******.**.jp | ***,*** | ||
| *********.**.jp | ***,*** | ||
| **************.org | ***,*** |
FAQ