CVE-2025-13342: Frontend Admin by DynamiApps <= 3.28.20 - Unauthenticated Arbitrary Options Update
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to, and including, 3.28.20. This is due to insufficient capability checks and input validation in the ActionOptions::run() save handler. This makes it possible for unauthenticated attackers to modify critical WordPress options such as userscanregister, defaultrole, and adminemail via submitting crafted form data to public frontend forms.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13342?
CVE-2025-13342 has been classified as a high severity vulnerability due to unauthorized modification of arbitrary WordPress options.
How do I fix CVE-2025-13342?
To fix CVE-2025-13342, update the DynamiApps Frontend Admin plugin to version 3.28.21 or later.
Who is affected by CVE-2025-13342?
All users of the DynamiApps Frontend Admin plugin for WordPress on versions up to and including 3.28.20 are affected by CVE-2025-13342.
What type of vulnerability is CVE-2025-13342?
CVE-2025-13342 is an authorization vulnerability due to insufficient capability checks and input validation.
Can CVE-2025-13342 be exploited remotely?
Yes, CVE-2025-13342 can be exploited remotely by attackers to modify WordPress options without proper authorization.