---
id: CVE-2026-81346
title: >-
  The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not
  perform a capability check on one of its AJAX actions, allowing any
  authenticated user, such as a subscriber, to delete arbitrary membership
  plans.
summary: >-
  The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not
  perform a capability check on one of its AJAX actions, allowing any
  authenticated user, such as a subscriber, to delete arbitrary membership
  plans.
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
published: '2026-08-29'
updated: '2026-08-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81346'
references:
  - url: 'https://wpscan.com/vulnerability/0fee8405-24c3-470e-b16d-7c839cba6038/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00254
epssPercentile: 0.15077
ingestedAt: '2026-08-30T07:49:08.218Z'
---

## Overview

The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
