Impact
The vulnerability allows an unauthenticated user to gain administrative privileges within a WordPress site that uses the Frontend Admin by DynamiApps plugin. By exploiting a flaw in the plugin’s access control, an attacker can elevate their privileges to a level that can modify site content, manage settings, and potentially execute arbitrary code. This increase in privileges undermines confidentiality, integrity, and availability of the website.
Affected Systems
Any WordPress site running the Frontend Admin by DynamiApps plugin version 3.29.10 or earlier is affected. The exact API endpoints or page paths are not detailed, but any instance of the vulnerable plugin installation is at risk.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. EPSS is not available, and the vulnerability is not listed in CISA KEV, suggesting a lower known exploitation prevalence. Although the exact attack vector is not specified, it is inferred that the vulnerability can be exploited via the plugin’s frontend interfaces, which are publicly accessible, allowing an unauthenticated attacker to trigger the privilege escalation by interacting with the plugin’s exposed forms or URLs.
OpenCVE Enrichment