CVE-2026-81346

Published: Ago 29, 2026 Last Modified: Ago 29, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans.

https://wpscan.com/vulnerability/0fee8405-24c3-470e-b16d-7c839cba6038/