CVE-2025-14736

CRITICAL

Frontend Admin by DynamiApps <3.28.25 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-14736. PoCs published by hyunchiya.

AI-analyzed exploit summary This repository contains a Go-based mass exploit tool for CVE-2025-14736, targeting unauthenticated privilege escalation in the Frontend Admin by DynamiApps WordPress plugin. The exploit manipulates the user registration form to assign an administrator role to a newly created user.

Description

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.29. This is due to insufficient validation of user-supplied role values in the 'validate_value', 'pre_update_value', and 'get_fields_display' functions. This makes it possible for unauthenticated attackers to register as administrators and gain complete control of the site, granted they can access a user registration form containing a Role field.

Exploits (1)

nomisec WORKING POC
by hyunchiya · poc
https://github.com/hyunchiya/CVE-2025-14736

This repository contains a Go-based mass exploit tool for CVE-2025-14736, targeting unauthenticated privilege escalation in the Frontend Admin by DynamiApps WordPress plugin. The exploit manipulates the user registration form to assign an administrator role to a newly created user.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Frontend Admin by DynamiApps (WordPress plugin) <= 3.28.25
No auth needed
Prerequisites: Target has vulnerable plugin installed · Frontend registration form is accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0066
EPSS Percentile 46.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-269
Status published
Products (2)
shabti/Frontend Admin by DynamiApps < 3.28.25
shabti/Frontend Admin by DynamiApps < 3.28.29
Published Jan 09, 2026
Tracked Since Feb 18, 2026