Impact
The vulnerability is a stored cross‑site scripting flaw triggered by an unsanitized "tag" shortcode attribute in the Frontend Admin by DynamiApps plugin. An authenticated user with Contributor or higher privileges can store arbitrary JavaScript code in that attribute. When a page using the shortcode is displayed, the script runs in the browsers of any visitor to that page, enabling client‑side code execution on the site.
Affected Systems
WordPress sites running Frontend Admin by DynamiApps plugin version 3.29.11 or earlier. Any site that has this plugin installed and grants Contributor or higher roles to users is vulnerable.
Risk and Exploitability
The CVSS score of 6.4 denotes moderate severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. Because exploitation requires authenticated Contributor+ access, the attack surface is limited to sites that grant such privileges. An attacker who obtains these credentials could cause arbitrary JavaScript execution for all visitors to the affected pages.
OpenCVE Enrichment