CVE-2025-14741 PUBLISHED

Frontend Admin by DynamiApps <= 3.28.25 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via 'delete post' Form Element

Assigner: Wordfence
Reserved: 15.12.2025 Published: 09.01.2026 Updated: 09.01.2026

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modification and deletion due to a missing capability check on the 'delete_object' function in all versions up to, and including, 3.28.25. This makes it possible for unauthenticated attackers to delete arbitrary posts, pages, products, taxonomy terms, and user accounts.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS Score: 9.1

Product Status

Vendor shabti
Product Frontend Admin by DynamiApps
Versions Default: unaffected
  • affected from * to 3.28.25 (incl.)

Credits

  • andrea bocchetti finder

References

Problem Types

  • CWE-862 Missing Authorization CWE