CVE-2025-14736 - Frontend Admin by DynamiApps <= 3.28.25 - unauthenticated privilege escalation t

CVE-2025-14736 - Frontend Admin by DynamiApps <= 3.28.25 - unauthenticated privilege escalation t

CVE ID : CVE-2025-14736 Published : Jan. 9, 2026, 6:34 a.m. | 32 minutes ago Description : The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.25. This is due to insufficient validation of user-supplied role values in the 'validate_value', 'pre_update_value', and 'get_fields_display' functions. This makes it possible for unauthenticated attackers to register as administrators and gain complete control of the site, granted they can access a user registration form containing a Role field. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Published
Jan. 9, 2026
Affected Product: WordPress
Impact: Privilege Escalation

Source: Telegram CVE Monitor