CVE-2025-14736
CRITICALFrontend Admin by DynamiApps <3.28.25 - Privilege Escalation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-14736. PoCs published by hyunchiya.
AI-analyzed exploit summary This repository contains a Go-based mass exploit tool for CVE-2025-14736, targeting unauthenticated privilege escalation in the Frontend Admin by DynamiApps WordPress plugin. The exploit manipulates the user registration form to assign an administrator role to a newly created user.
Description
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.29. This is due to insufficient validation of user-supplied role values in the 'validate_value', 'pre_update_value', and 'get_fields_display' functions. This makes it possible for unauthenticated attackers to register as administrators and gain complete control of the site, granted they can access a user registration form containing a Role field.
Exploits (1)
This repository contains a Go-based mass exploit tool for CVE-2025-14736, targeting unauthenticated privilege escalation in the Frontend Admin by DynamiApps WordPress plugin. The exploit manipulates the user registration form to assign an administrator role to a newly created user.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H