Back to overview

CVE-2025-13342

CRITICAL
9.8
CVSS 3.1
Description
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to, and including, 3.28.20. This is due to insufficient capability checks and input validation in the ActionOptions::run() save handler. This makes it possible for unauthenticated attackers to modify critical WordPress options such as users_can_register, default_role, and admin_email via submitting crafted form data to public frontend forms.

Metadata

CVE ID
CVE-2025-13342
State
PUBLISHED
Assigner
Wordfence
Reserved
2025-11-17 23:15 UTC
Published
2025-12-03 12:29 UTC
Last updated
2026-04-08 16:56 UTC
Primary CWE
CWE-862
CWE-862 Missing Authorization
Vendor / Product
shabti / Frontend Admin by DynamiApps
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
shabti Frontend Admin by DynamiApps 0 ≤ 3.28.20
Weakness (CWE)
CWESourceDescription
CWE-862 cna CWE-862 Missing Authorization
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview