
Proof-of-concept and lab reproduction for CVE-2026-75816, an unauthenticated WordPress Frontend Admin account takeover via admin-ajax form submission.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · [email protected] · CVE-2026-75816
Frontend Admin by DynamiApps 3.29.11 - shabti
I am @abraxas_null. Loopback lab. The client is CVE-2026-75816-Abraxas-Labs.py.
user_1 is not a post. Unauthenticated admin-ajax.php frontend_admin/form_submit. ActionPost::conditions_logic() returns early when the object id is non-numeric (user_1), skipping current_user_can('edit_post'). The Email field pre_update_value in 3.29.11 has no edit_user check and wp_update_users user 1's email. NVD lists through 3.29.12; changelog 3.29.12 added that check. Lab is 3.29.11. Current is 3.29.13.
| CVE | CVE-2026-75816 · CVE.org |
| CWE | CWE-287 |
| CVSS | Critical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Product | Frontend Admin by DynamiApps |
| Affected | all versions through 3.29.11 (NVD lists 3.29.12; 3.29.12 added the Email-field edit_user check) |
| Patched | 3.29.12 and later |
| Auth | none |
| License | GNU Affero GPL v3.0 |
| Lab | 127.0.0.1 only |
Guest POST changes the administrator email. Password reset to that address is account takeover. The lab stops at the email change. I am not printing a lost-password recipe aimed at someone else's admin.
Wordfence named pre_update_value and user_1. I read conditions_logic, then the Email field, then harvested the public form.
GET /fea-lab/. Pull _acf_nonce, _acf_objects, the user_email field key. POST acff[post][<key>][email protected]. GET /?fea_lab_email=1. Small ajax JSON Post updated, then the new address.
Wrong turns: action=pre_update_value or parse_array (function names are not routes); hard-coded nonce; numeric post_id (then edit_post actually runs and a guest is denied); who_can_see not all; 3.29.12; treating [email protected] still in the body as success.
Port 8088. Frontend Admin 3.29.11. Public form /fea-lab/, who_can_see=all, object user_1.
Target only 127.0.0.1:8088 (or the loopback you bound).
cd lab
docker compose up --force-recreate
./run.sh
Witness: GET /?fea_lab_email=1 is [email protected]. Generic form HTML or [email protected] is not it.
Ways to lose without learning anything:
[email protected] still the admin email0 / -1 / permission JSON without the email changeUpdate Frontend Admin by DynamiApps to 3.29.12 or newer (current 3.29.13). Re-run CVE-2026-75816-Abraxas-Labs.py against the patched build: the admin email must not change.
plugins.trac.wordpress.org/changeset/3664865/acf-frontend-form-element
www.wordfence.com/threat-intel/vulnerabilities/id/f1637a3b-7b0f-485d-9d19-4f711f8c671b?source=cve
Plugin directory: acf-frontend-form-element
Trac browser: plugins.trac.wordpress.org/acf-frontend-form-element
SVN tags: plugins.svn.wordpress.org/acf-frontend-form-element
Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null
GNU Affero GPL v3.0. See LICENSE.
The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.