GHSA-x776-485v-f3r3MediumCVSS 4.3
The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability...
🔗 CVE IDs covered (1)
📋 Description
The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans.