What is CVE-2026-15606?
The Frontend Admin by DynamiApps plugin for WordPress has an authorization bypass vulnerability in versions up to and including 3.29.9. The plugin fails to properly verify that a user is authorized to perform an action, making it possible for authenticated attackers with subscriber-level access to perform unauthorized operations. Users should update the plugin to the latest version immediately.
Azərbaycanca: Frontend Admin by DynamiApps WordPress plaqini 3.29.9 daxil olmaqla bütün versiyalarda avtorizasiya zəifliyi aşkarlanıb. Bu, autentifikasiya olunmuş abunəçi səviyyəli hücumçulara icazəsiz əməliyyatlar aparmağa imkan verir. Plaqin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: DynamiApps
FAQ2
Which plugin is affected by CVE-2026-15606 and what versions are vulnerable?
The vulnerability affects the Frontend Admin by DynamiApps WordPress plugin in versions up to and including 3.29.9.
What level of access does an attacker need to exploit CVE-2026-15606?
Authenticated attackers with subscriber-level access can exploit this vulnerability to perform unauthorized operations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.