Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-14736

Опубликовано: 09 янв. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.25. This is due to insufficient validation of user-supplied role values in the 'validate_value', 'pre_update_value', and 'get_fields_display' functions. This makes it possible for unauthenticated attackers to register as administrators and gain complete control of the site, granted they can access a user registration form containing a Role field.

EPSS

Процентиль: 17%
0.00053
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 9.8
github
29 дней назад

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.25. This is due to insufficient validation of user-supplied role values in the 'validate_value', 'pre_update_value', and 'get_fields_display' functions. This makes it possible for unauthenticated attackers to register as administrators and gain complete control of the site, granted they can access a user registration form containing a Role field.

EPSS

Процентиль: 17%
0.00053
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-269