CVE-2026-15606
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level and above permissions, to reset the password of any user on the site, including administrators, leading to full account takeover and complete site compromise. Exploitation requires the attacker to hold a valid encrypted Current-User token obtained by accessing any Edit User form they are legitimately authorized to submit, which they then use as a known-plaintext base for the CBC bit-flipping forgery.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Base score: 8.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.59%
- Percentile among all scored CVEs: 46
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1210Exploitation of Remote Serviceslateral movement75 % - Primary impact
T1078.001Default Accountsstealth · persistence · privilege escalation · initial access85 % - Secondary impact
T1068Exploitation for Privilege Escalationprivilege escalation75 % - Secondary impact
T1098.002Additional Email Delegate Permissionspersistence · privilege escalation80 %
AV:N, PR:L sin interacción del usuario apunta a T1210 (servicios remotos con privilegios). El ataque logra takeover de cuentas administrativas (T1078.001), manipulación de cuentas (T1098.002) y escalada de privilegios local (T1068) hacia control total del sitio.
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-862
References
- https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.5/main/frontend/fields/user/class-user-password.php#L146
- https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.5/main/frontend/forms/classes/submit.php#L36
- https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.5/main/frontend/forms/classes/submit.php#L54
- https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.5/main/helpers.php#L687
- https://plugins.trac.wordpress.org/changeset/3633030/acf-frontend-form-element
- https://www.wordfence.com/threat-intel/vulnerabilities/id/e5aa9b71-67e4-4049-8dd4-23b76dbd87bb?source=cve
Raw JSON (NVD)
Show
{
"id": "CVE-2026-15606",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-15606",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-08-12T13:00:32.247209Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@wordfence.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@wordfence.com",
"affectedData": [
{
"vendor": "shabti",
"product": "Frontend Admin by DynamiApps",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "3.29.9"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-08-11T21:17:27.847",
"references": [
{
"url": "https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.5/main/frontend/fields/user/class-user-password.php#L146",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.5/main/frontend/forms/classes/submit.php#L36",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.5/main/frontend/forms/classes/submit.php#L54",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.5/main/helpers.php#L687",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3633030/acf-frontend-form-element",
"source": "security@wordfence.com"
},
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e5aa9b71-67e4-4049-8dd4-23b76dbd87bb?source=cve",
"source": "security@wordfence.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security@wordfence.com",
"description": [
{
"lang": "en",
"value": "CWE-862"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level and above permissions, to reset the password of any user on the site, including administrators, leading to full account takeover and complete site compromise. Exploitation requires the attacker to hold a valid encrypted Current-User token obtained by accessing any Edit User form they are legitimately authorized to submit, which they then use as a known-plaintext base for the CBC bit-flipping forgery."
}
],
"lastModified": "2026-08-12T21:00:52.257",
"sourceIdentifier": "security@wordfence.com"
}