What is CVE-2026-13609?
This vulnerability affects the Frontend Admin by DynamiApps WordPress plugin before version 3.29.9. An unauthenticated visitor can submit a double-encoded HTML payload that bypasses sanitization by having its HTML entities decoded afterwards, resulting in stored live tags. Users should immediately upgrade to version 3.29.9 or higher.
Azərbaycanca: Bu boşluq Frontend Admin by DynamiApps WordPress plaginində 3.29.9 versiyasından əvvəl mövcuddur. Təsdiqlənməmiş ziyarətçi sanitizasiya prosesini keçmək üçün ikiqat kodlanmış HTML yükü göndərərək, sonradan kodlanmış HTML varlıqlarının dekodlanması nəticəsində aktiv teqlərin saxlanmasına səbəb olur. Plagin sahibləri dərhal 3.29.9 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: DynamiApps
FAQ2
Which WordPress plugin is affected by the CVE-2026-13609 vulnerability?
This vulnerability affects the Frontend Admin by DynamiApps plugin.
What should plugin owners do to protect against the CVE-2026-13609 vulnerability?
Users should immediately upgrade to version 3.29.9 or higher.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.