The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'fea_encrypt' function in all versions up to, and including, 3.19.4. This makes it possible for unauthenticated attackers to manipulate the user processing forms, which can be used to add and edit administrator user for privilege escalation, or to automatically log in users for authentication bypass, or manipulate the post processing form that can be used to inject arbitrary web scripts. This can only be exploited if the 'openssl' php extension is not loaded on the server.
References
Configurations
History
05 Jun 2025, 20:27
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-754 | |
First Time |
Dynamiapps frontend Admin
Dynamiapps |
|
CPE | cpe:2.3:a:dynamiapps:frontend_admin:*:*:*:*:*:wordpress:*:* | |
References | () https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.18.15/main/helpers.php#L617 - Product | |
References | () https://plugins.trac.wordpress.org/changeset/3073379/acf-frontend-form-element#file4 - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/a2d22c5d-5ef5-4920-a1b5-e8284394c7e8?source=cve - Third Party Advisory |
21 Nov 2024, 09:30
Type | Values Removed | Values Added |
---|---|---|
References | () https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.18.15/main/helpers.php#L617 - | |
References | () https://plugins.trac.wordpress.org/changeset/3073379/acf-frontend-form-element#file4 - | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/a2d22c5d-5ef5-4920-a1b5-e8284394c7e8?source=cve - | |
Summary |
|
02 May 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-02 17:15
Updated : 2025-06-05 20:27
NVD link : CVE-2024-3729
Mitre link : CVE-2024-3729
CVE.ORG link : CVE-2024-3729
JSON object : View
Products Affected
dynamiapps
- frontend_admin
CWE
CWE-754
Improper Check for Unusual or Exceptional Conditions