Product
CVE-2026-18432 allows unauthenticated or subscriber-level attackers to escalate privileges to administrator via an improper authorization check in the Frontend Admin plugin for WordPress.