Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-75816 — Proof-of-concept and lab reproduction for CVE-2026-75816, an unauthenticated WordPress Frontend Admin account takeover via admin-ajax form submission. | Kitploit
Tools/GitHubGitHub/abraxas/cve-2026-75816
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingAuthenticationLabs & Practice
GitHubabraxas/cve-2026-75816

CVE-2026-75816

Proof-of-concept and lab reproduction for CVE-2026-75816, an unauthenticated WordPress Frontend Admin account takeover via admin-ajax form submission.

View Repository
233 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Abraxas Labs - CVE-2026-75816

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-75816

CVE-2026-75816

Frontend Admin by DynamiApps 3.29.11 - shabti

I am @abraxas_null. Loopback lab. The client is CVE-2026-75816-Abraxas-Labs.py.

user_1 is not a post. Unauthenticated admin-ajax.php frontend_admin/form_submit. ActionPost::conditions_logic() returns early when the object id is non-numeric (user_1), skipping current_user_can('edit_post'). The Email field pre_update_value in 3.29.11 has no edit_user check and wp_update_users user 1's email. NVD lists through 3.29.12; changelog 3.29.12 added that check. Lab is 3.29.11. Current is 3.29.13.

CVECVE-2026-75816 · CVE.org
CWECWE-287
CVSSCritical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ProductFrontend Admin by DynamiApps
Affectedall versions through 3.29.11 (NVD lists 3.29.12; 3.29.12 added the Email-field edit_user check)
Patched3.29.12 and later
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Guest POST changes the administrator email. Password reset to that address is account takeover. The lab stops at the email change. I am not printing a lost-password recipe aimed at someone else's admin.


How I found it

Wordfence named pre_update_value and user_1. I read conditions_logic, then the Email field, then harvested the public form.

GET /fea-lab/. Pull _acf_nonce, _acf_objects, the user_email field key. POST acff[post][<key>][email protected]. GET /?fea_lab_email=1. Small ajax JSON Post updated, then the new address.

Wrong turns: action=pre_update_value or parse_array (function names are not routes); hard-coded nonce; numeric post_id (then edit_post actually runs and a guest is denied); who_can_see not all; 3.29.12; treating [email protected] still in the body as success.


The lab

Port 8088. Frontend Admin 3.29.11. Public form /fea-lab/, who_can_see=all, object user_1.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml
  • lab/run.sh

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
./run.sh

Witness: GET /?fea_lab_email=1 is [email protected]. Generic form HTML or [email protected] is not it.

Ways to lose without learning anything:

  • [email protected] still the admin email
  • admin-ajax 0 / -1 / permission JSON without the email change
  • reverse shell
  • real password-reset to an attacker mailbox

The fix

Update Frontend Admin by DynamiApps to 3.29.12 or newer (current 3.29.13). Re-run CVE-2026-75816-Abraxas-Labs.py against the patched build: the admin email must not change.


References

  • CVE-2026-75816 · NVD

  • CVE-2026-75816 · CVE.org

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/fields/user/class-user-email.php#L127

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/forms/actions/post.php#L1001

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/forms/actions/post.php#L1224

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/forms/classes/display.php#L26

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/forms/classes/submit.php#L125

  • plugins.trac.wordpress.org/changeset/3664865/acf-frontend-form-element

  • www.wordfence.com/threat-intel/vulnerabilities/id/f1637a3b-7b0f-485d-9d19-4f711f8c671b?source=cve

  • github.com/advisories/GHSA-pv54-wq7v-wf7v

  • nvd.nist.gov/vuln/detail/CVE-2026-75816

  • Plugin directory: acf-frontend-form-element

  • Trac browser: plugins.trac.wordpress.org/acf-frontend-form-element

  • SVN tags: plugins.svn.wordpress.org/acf-frontend-form-element

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

Download Tool