CVE-2024-3729
Frontend Admin by DynamiApps <= 3.19.4 - Improper Missing Encryption Exception Handling to Form Manipulation
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'fea_encrypt' function in all versions up to, and including, 3.19.4. This makes it possible for unauthenticated attackers to manipulate the user processing forms, which can be used to add and edit administrator user for privilege escalation, or to automatically log in users for authentication bypass, or manipulate the post processing form that can be used to inject arbitrary web scripts. This can only be exploited if the 'openssl' php extension is not loaded on the server.
| CWE | CWE-636 |
| Vendor | shabti |
| Product | frontend admin by dynamiapps |
| Published | May 2, 2024 |
| Last Updated | Apr 8, 2026 |
Get instant alerts for shabti frontend admin by dynamiapps
Be the first to know when new critical vulnerabilities affecting shabti frontend admin by dynamiapps are published — delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H