Impact
The Frontend Admin by DynamiApps WordPress plugin contains a stored cross‑site scripting flaw caused by a kses bypass. The vulnerability is driven by the get_dynamic_values function, which performs a simple text replacement on post content without proper HTML‑aware parsing. An attacker with Contributor or higher privileges can inject arbitrary JavaScript into post bodies, which will execute for all users who view the affected pages.
Affected Systems
WordPress sites that have the Frontend Admin by DynamiApps plugin installed in any version up to and including 3.28.36. The plugin is maintained by DynamiApps and the impact applies to installations that have not yet upgraded beyond this version.
Risk and Exploitability
The attack takes place from an authenticated user with at least Contributor access. Based on the description, it is inferred that the attacker must create or edit a post via the plugin’s front‑end form and supply malicious script payloads that bypass the plugin’s filtering. Once stored, the script executes in the browser whenever the post is viewed, enabling session hijacking, phishing, or other client‑side attacks. The CVSS score of 6.4 indicates moderate severity. The EPSS score is not available, so the likelihood of exploitation is uncertain, and the vulnerability is not listed in the CISA KEV catalog. Because exploitation requires authenticated site access, the risk is limited to contributors and site users, but the impact on all site visitors who view the affected content can be significant.
OpenCVE Enrichment