Junglewise Threat Intelligence

CVE-2026-66638: Frontend Admin by DynamiApps cross-site scripting

CVE-2026-66638 · Severity: medium · CVSS 6.5 · Published 2026-08-18

Executive brief

Frontend Admin by DynamiApps is a WordPress plugin that allows website administrators to manage site content and settings from the frontend. A cross-site scripting (XSS) vulnerability in versions 3.29.10 and earlier allows contributors to inject malicious scripts that could steal visitor data or hijack user accounts. Exploitation requires a privileged user with contributor-level access to perform an action such as clicking a link or submitting a form.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in the Frontend Admin by DynamiApps WordPress plugin affecting versions up to 3.29.10. The vulnerability exists due to insufficient input validation or output encoding in the plugin's form handling or data processing logic. An authenticated attacker with Contributor role or higher privileges can inject malicious JavaScript that will execute in the context of an administrator's browser when they interact with the crafted content. The attack requires user interaction (e.g., clicking a link or visiting a crafted page) and results in potential theft of session cookies, sensitive data, or account takeover. The vulnerability has been patched in version 3.29.11.

Affected products

  • DynamiApps Frontend Admin <=3.29.10

Timeline

  • 2026-07-09: disclosed: Reported by Ananda Dhakal (Patchstack)
  • 2026-08-18: advisory: Published by Patchstack and NVD
  • 2026-08-18: patched: Fixed in version 3.29.11

References

Related threats