Impact
The Frontend Admin by DynamiApps WordPress plugin before version 3.29.7 fails to perform capability checks on taxonomy term creation, modification, and deletion. An authenticated user with low privileges, such as a Subscriber, can therefore add, rename, or delete arbitrary taxonomy terms. This can be used to hide, redirect, or manipulate content organization, potentially compromising the site’s integrity and presentation.
Affected Systems
Any WordPress site running the Frontend Admin by DynamiApps plugin with a version earlier than 3.29.7 is affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, indicating moderate severity. The EPSS score is less than 1 %, suggesting a low likelihood of exploitation at present. It is not listed in the CISA KEV catalog. The attack vector requires that the attacker is an authenticated user with a low‑privilege role, as described in the CVE description; no further prerequisites are specified. If an attacker can assume a Subscriber account, they can manipulate taxonomy terms without authorization.
OpenCVE Enrichment