CVE-2024-11721: Frontend Admin by DynamiApps <= 3.24.5 - Unauthenticated Privilege Escalation
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.24.5. This is due to insufficient controls on the user role select field when utilizing the 'Role' field in a form. This makes it possible for unauthenticated attackers to create new administrative user accounts, even when the administrative user role has not been provided as an option to the user, granted that unauthenticated users have been provided access to the form.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11721?
CVE-2024-11721 is classified as a privilege escalation vulnerability.
How do I fix CVE-2024-11721?
To fix CVE-2024-11721, update the Frontend Admin plugin by DynamiApps to version 3.24.6 or higher.
What versions are affected by CVE-2024-11721?
CVE-2024-11721 affects all versions of the Frontend Admin plugin for WordPress up to and including 3.24.5.
What type of attack can CVE-2024-11721 facilitate?
CVE-2024-11721 can facilitate unauthorized privilege escalation attacks on WordPress sites.
Who is the vendor for CVE-2024-11721?
The vendor for CVE-2024-11721 is DynamiApps.