The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to, and including, 3.28.20. This is due to insufficient capability checks and input validation in the ActionOptions::run() save handler. This makes it possible for unauthenticated attackers to modify critical WordPress options such as users_can_register, default_role, and admin_email via submitting crafted form data to public frontend forms.
Metrics
Affected Vendors & Products
References
History
Thu, 04 Dec 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dynamiapps
Dynamiapps frontend Admin Wordpress Wordpress wordpress |
|
| Vendors & Products |
Dynamiapps
Dynamiapps frontend Admin Wordpress Wordpress wordpress |
Wed, 03 Dec 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Dec 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to, and including, 3.28.20. This is due to insufficient capability checks and input validation in the ActionOptions::run() save handler. This makes it possible for unauthenticated attackers to modify critical WordPress options such as users_can_register, default_role, and admin_email via submitting crafted form data to public frontend forms. | |
| Title | Frontend Admin by DynamiApps <= 3.28.20 - Unauthenticated Arbitrary Options Update | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-12-03T12:29:55.422Z
Updated: 2025-12-03T14:01:05.990Z
Reserved: 2025-11-17T23:15:13.995Z
Link: CVE-2025-13342
Updated: 2025-12-03T14:00:32.953Z
Status : Awaiting Analysis
Published: 2025-12-03T13:16:02.007
Modified: 2025-12-04T17:15:08.283
Link: CVE-2025-13342
No data.