CVE-2025-49303: WordPress Frontend Admin by DynamiApps plugin <= 3.28.7 - Arbitrary File Download Vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps acf-frontend-form-element allows Path Traversal.This issue affects Frontend Admin by DynamiApps: from n/a through <= 3.28.7.
Other sources
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps allows Path Traversal. This issue affects Frontend Admin by DynamiApps: from n/a through 3.28.7.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49303?
CVE-2025-49303 is considered a critical severity vulnerability due to its potential for path traversal attacks.
How do I fix CVE-2025-49303?
To fix CVE-2025-49303, upgrade DynamiApps Frontend Admin to version 3.28.8 or later.
What types of systems are affected by CVE-2025-49303?
CVE-2025-49303 affects DynamiApps Frontend Admin and WordPress Frontend Admin versions up to 3.28.7.
What risks are associated with CVE-2025-49303?
The risks associated with CVE-2025-49303 include unauthorized access to sensitive files and potential exploitation of the server.
Is CVE-2025-49303 being actively exploited?
There is evidence that CVE-2025-49303 could be actively exploited, hence immediate remediation is recommended.