Missing Authorization
4 records21.1%First: 2022. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 19 vulnerability records associated with Frontend Admin by DynamiApps, published between 2022 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2022 | 1 | |
| 2023 | 2 | |
| 2024 | 4 | |
| 2025 | 4 | |
| 2026 | 8 |
| Severity | Records | Share |
|---|---|---|
| Critical | 5 | 26.3% |
| High | 7 | 36.8% |
| Medium | 7 | 36.8% |
First: 2022. Latest: 2026.
First: 2023. Latest: 2026.
First: 2024. Latest: 2026.
First: 2024. Latest: 2026.
First: 2024. Latest: 2026.
First: 2023. Latest: 2023.
First: 2025. Latest: 2025.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
3.28.293.29.33.29.13.28.323.28.243.28.263.28.303.28.213.28.53.28.83.25.183.25.23.25.13.19.53.18.43.8.03.3.33Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-3.28.8 | Frontend Admin by DynamiApps <= 3.28.28 - Authenticated (Administrator+) SQL Injection via 'order' Parameter | May 28, 2026 | 3.28.29 | Medium |
*-3.29.2 | Frontend Admin by DynamiApps <= 3.29.2 - Missing Authorization to Authenticated (Subscriber+) Account Takeover via 'user_id' URL Query Parameter | May 27, 2026 | 3.29.3 | High |
*-3.29.2 | Frontend Admin by DynamiApps <= 3.29.2 - Unauthenticated Privilege Escalation via Form Configuration Injection | May 27, 2026 | 3.29.3 | High |
*-3.28.36 | Frontend Admin by DynamiApps <= 3.28.36 - Unauthenticated Privilege Escalation via Edit User Form | May 14, 2026 | 3.29.1 | High |
*-3.28.31 | Frontend Admin by DynamiApps <= 3.28.31 - Authenticated (Editor+) PHP Object Injection via 'post_content' of Admin Form Posts | March 25, 2026 | 3.28.32 | High |
*-3.28.23 | Frontend Admin by DynamiApps <= 3.28.23 - Unauthenticated Stored Cross-Site Scripting via 'update_field' | January 8, 2026 | 3.28.24 | High |
*-3.28.25 | Frontend Admin by DynamiApps <= 3.28.25 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via 'delete post' Form Element | January 8, 2026 | 3.28.26 | Critical |
*-3.28.29 | Frontend Admin by DynamiApps <= 3.28.29 - Unauthenticated Privilege Escalation to Administrator via Role Form Field | January 8, 2026 | 3.28.30 | Critical |
*-3.28.20 | Frontend Admin by DynamiApps <= 3.28.20 - Unauthenticated Arbitrary Options Update | December 3, 2025 | 3.28.21 | Critical |
*-3.28.3 | Frontend Admin by DynamiApps <= 3.28.3 - Authenticated (Subscriber+) SQL Injection | August 12, 2025 | 3.28.5 | Medium |
*-3.28.7 | Frontend Admin by DynamiApps <= 3.28.7 - Authenticated (Editor+) Arbitrary File Deletion | June 26, 2025 | 3.28.8 | Medium |
*-3.25.17 | Frontend Admin by DynamiApps <= 3.25.17 - Reflected Cross-Site Scripting | February 23, 2025 | 3.25.18 | Medium |
*-3.25.1 | Frontend Admin by DynamiApps <= 3.25.1 - Unauthenticated SQL Injection | December 20, 2024 | 3.25.2 | Medium |
*-3.24.5 | Frontend Admin by DynamiApps <= 3.24.5 - Unauthenticated Privilege Escalation | December 13, 2024 | 3.25.1 | High |
*-3.24.5 | Frontend Admin by DynamiApps <= 3.24.5 - Unauthenticated Stored Cross-Site Scripting | December 13, 2024 | 3.25.1 | High |
*-3.19.4 | Frontend Admin by DynamiApps <= 3.19.4 - Improper Missing Encryption Exception Handling to Form Manipulation | April 18, 2024 | 3.19.5 | Critical |
*-3.18.3 | Frontend Admin by DynamiApps Plugin <= 3.18.3 - Unauthenticated Arbitrary File Upload | December 27, 2023 | 3.18.4 | Critical |
*-3.7.11 | Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get | July 18, 2023 | 3.8.0 | Medium |
[*, 3.3.33) | Freemius SDK <= 2.4.2 - Missing Authorization Checks | March 4, 2022 | 3.3.33 | Medium |
Selected source records
Published: May 28, 2026
Published: May 27, 2026
Published: May 27, 2026
Published: May 14, 2026
Published: March 25, 2026
Published: January 8, 2026
Published: January 8, 2026
Published: January 8, 2026
Published: January 8, 2026
Published: December 3, 2025
Published: December 27, 2023
Published: April 18, 2024
Published: January 8, 2026
Published: May 14, 2026
Published: May 27, 2026
Published: May 27, 2026
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.