The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'fea_encrypt' function in all versions up to, and including, 3.19.4. This makes it possible for unauthenticated attackers to manipulate the user processing forms, which can be used to add and edit administrator user for privilege escalation, or to automatically log in users for authentication bypass, or manipulate the post processing form that can be used to inject arbitrary web scripts. This can only be exploited if the 'openssl' php extension is not loaded on the server.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Jun 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dynamiapps
Dynamiapps frontend Admin |
|
Weaknesses | CWE-754 | |
CPEs | cpe:2.3:a:dynamiapps:frontend_admin:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Dynamiapps
Dynamiapps frontend Admin |

Status: PUBLISHED
Assigner: Wordfence
Published: 2024-05-02T16:52:28.332Z
Updated: 2024-08-01T20:20:01.048Z
Reserved: 2024-04-12T18:15:54.930Z
Link: CVE-2024-3729

Updated: 2024-08-01T20:20:01.048Z

Status : Analyzed
Published: 2024-05-02T17:15:30.730
Modified: 2025-06-05T20:27:10.677
Link: CVE-2024-3729

No data.