PT-2026-44215 · Shabti+1 · Frontend Admin By Dynamiapps+1

·

CVE-2026-6226

·

Published

2026-05-27

·

Updated

2026-05-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Frontend Admin by DynamiApps versions prior to 3.29.3
Description Insecure form submission handling allows unauthenticated privilege escalation. The issue occurs when the validate form() function processes an array in the acf form parameter instead of a form ID, bypassing database lookups. Subsequently, the create record() function preserves attacker-supplied data, and the run() function in the user action utilizes attacker-controlled field definitions from $form['fields']. This allows the pre update value() validation of the role field to read role options from the malicious definition, enabling an attacker to specify the administrator role and create unauthorized administrator accounts by injecting a custom form configuration.
Recommendations Update to a version newer than 3.29.2.

Fix

DoS

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6226

Affected Products

Frontend Admin By Dynamiapps
Acf-Frontend-Form-Element