Impact
The vulnerability is a broken access control flaw that allows a user with subscriber privileges to perform actions normally restricted to higher‑privileged roles. This type of flaw is classified as CWE‑862. An attacker exploiting this weakness could gain unauthorized access to sensitive data, modify content, or impersonate users with elevated privileges, thereby compromising the confidentiality, integrity, and possibly availability of the WordPress site. The impact extends to any subscriber account that is authenticated and logged into the site.
Affected Systems
WordPress sites that have the Frontend Admin by DynamiApps plugin from the vendor Shabti Kaplan installed in any version up to and including 3.29.10 are affected. No other vendors or product versions are listed as impacted.
Risk and Exploitability
The issue carries a CVSS score of 7.1, indicating a high severity level. The EPSS score is not available, but the absence of an EPSS rating does not diminish the serious nature of the flaw. The vulnerability is not listed in CISA’s KEV catalog. Attackers can leverage the flaw via the normal web interface that subscribers use, making it potentially exploitable remotely by anyone with subscriber access. No specific exploit code has been publicized, but the nature of the flaw means that an attacker could manually trigger the unauthorized actions through the plugin’s frontend interface.
OpenCVE Enrichment