Description
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.25. This is due to insufficient validation of user-supplied role values in the 'validate_value', 'pre_update_value', and 'get_fields_display' functions. This makes it possible for unauthenticated attackers to register as administrators and gain complete control of the site, granted they can access a user registration form containing a Role field.
Problem types
CWE-269 Improper Privilege Management
Product status
* (semver)
Timeline
| 2025-12-12: | Discovered |
| 2025-12-15: | Vendor Notified |
| 2026-01-08: | Disclosed |
Credits
andrea bocchetti
References
www.wordfence.com/...-6588-490d-8947-3077ec4a9045?source=cve
plugins.trac.wordpress.org/...end/fields/user/class-role.php