Frontend Admin by DynamiApps <= 3.28.31 - Authenticated (Editor+) PHP Object Injection via 'post_content' of Admin Form Posts
Frontend Admin by DynamiApps
Minimum safe version
3.28.32
Update to 3.28.32 or later to address 18 fixable vulnerabilities
CVE-2025-14736
CVE-2025-14741
CVE-2025-14937
CVE-2025-13342
CVE-2025-49267
CVE-2025-49303
CVE-2025-26987
CVE-2024-11722
CVE-2024-11721
CVE-2024-11720
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-3729
WordPress Frontend Admin by DynamiApps Plugin <= 3.18.3 is vulnerable to Arbitrary File Upload
WordPress ACF Frontend – Add and edit posts, pages, users and more all from the frontend Plugin <= 3.7.11 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress "ACF Frontend – Add and edit posts, pages, users and more all from the frontend" plugin < 3.3.33 - Sensitive Information Disclosure vulnerability
WordPress "ACF Frontend – Add and edit posts, pages, users and more all from the frontend" plugin < 3.3.33 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability