CVE-2026-13609: Stored Cross-Site Scripting in Frontend Admin by DynamiApps WordPress Plugin
The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 is vulnerable to stored cross-site scripting. An unauthenticated attacker can submit a double-encoded payload that is stored and later output without escaping, allowing for XSS execution in the browser of any user who views the submitted value. This vulnerability has a CVSS score of 8.8, indicating high severity.