Loading market data...
← Back to CVE feed

CVE-2026-11867

MEDIUM CVSS 6.5 View on NVD ↗

Description

The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated users with low privileges (such as Subscribers) to create, rename, and delete arbitrary taxonomy terms.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Published: Jul 30, 2026 06:24 UTC Modified: Jul 30, 2026 16:45 UTC