CVE 9.8 CRITICAL

Frontend Admin by DynamiApps <= 3.28.20 - Unauthenticated Arbitrary Options Update_CVE-2025-13342

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to, and including, 3.28.20. This is due to insufficient capability checks and input validation in the ActionOptions::run() save handler. This makes it possible for unauthenticated attackers to modify critical WordPress options such as users_can_register, default_role, and admin_email via submitting crafted form data to public frontend forms.

AI Analysis

Unauthenticated arbitrary options update vulnerability in Frontend Admin by DynamiApps plugin for WordPress

Basic Information

ID CVE-2025-13342
Source Wordfence
Published Dec 3, 2025 at 12:29
Modified Dec 3, 2025 at 14:01

Affected Product

Vendor shabti
Product Frontend Admin by DynamiApps
Version *
Affected Versions shabti Frontend Admin by DynamiApps *

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor DynamiApps
Product Frontend Admin
Version 3.28.20 and below

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.