Impact
An unsanitized input field in the WordPress Frontend Admin by DynamiApps plugin allows administrators to inject arbitrary SQL statements, which can lead to unauthorized database read, modification, or deletion. The flaw is a classic SQL injection (CWE‑89) that can compromise the confidentiality and integrity of the site’s data and potentially enable further privilege escalation.
Affected Systems
WordPress sites using the Frontend Admin by DynamiApps plugin from vendor Shabti Kaplan, versions 3.29.13 and earlier are vulnerable. The specific plugin and all earlier releases below 3.29.14 are impacted.
Risk and Exploitability
The CVSS score of 7.6 classifies this flaw as high severity, indicating that exploitation would have significant impact if an attacker can reach the vulnerable input. EPSS data is not available, preventing a precise probability assessment, but the plugin’s web‑based forms make remote exploitation plausible. The vulnerability is not listed in the CISA KEV catalog, yet the high CVSS and remote nature warrant immediate attention.
OpenCVE Enrichment