What is CVE-2026-11867?
The Frontend Admin by DynamiApps WordPress plugin before version 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations. This vulnerability allows authenticated users with low privileges, such as Subscribers, to create, rename, and delete arbitrary taxonomy terms.
Azərbaycanca: Frontend Admin by DynamiApps WordPress plaqini 3.29.7 versiyasından əvvəl taksonomiya termini əməliyyatlarında (yaratma, dəyişmə, silmə) səlahiyyət yoxlaması aparmır. Bu zəiflik Subscriber kimi aşağı səviyyəli autentifikasiya olunmuş istifadəçilərə ixtiyari taksonomiya terminlərini manipulyasiya etməyə imkan verir.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: DynamiApps
FAQ2
Which versions of the Frontend Admin by DynamiApps plugin are affected by CVE-2026-11867?
All versions of the plugin before version 3.29.7 are affected by this vulnerability.
What does this vulnerability allow a user with Subscriber role to do?
This vulnerability allows authenticated users with low privileges, such as Subscribers, to create, rename, and delete arbitrary taxonomy terms.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.