Summary
CVE-2026-66662 is an unauthenticated privilege escalation vulnerability in the Frontend Admin by DynamiApps WordPress plugin (slug acf-frontend-form-element) in all versions up to and including 3.29.10. The flaw stems from incorrect privilege assignment (CWE-266) and allows an unauthenticated, network-based attacker to gain elevated permissions. It carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: Incorrect privilege assignment (CWE-266) in the plugin’s frontend form handling, allowing users to obtain permissions they should not be granted.
- Trigger conditions: Exploitable by an unauthenticated actor with no user interaction and no prior privileges.
- Attack vector: Network (remote, over HTTP/HTTPS to the affected WordPress site).
- Impact: Privilege escalation leading to full compromise of confidentiality, integrity, and availability of the affected site.
Affected software
- Frontend Admin by DynamiApps (plugin slug
acf-frontend-form-element) — all versions up to and including 3.29.10.
Severity
- CVSS v3.1 base score: 9.8 (Critical)
- Vector string:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: At the time of writing, 3.29.10 is the latest released version and no fixed version is available. Monitor the vendor for a release above 3.29.10 and upgrade as soon as a patched version is published.
- If no patch: Deactivate and remove the plugin until a fix is released. Where the plugin must remain active, restrict access to frontend form endpoints, place the site behind a web application firewall with rules to block anomalous form submissions, and audit user accounts and roles for unexpected privilege changes.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body:
/wp-content/plugins/acf-frontend-form-element/

