cleantalk
Vulnerabilities and Security Researches

Frontend Admin by DynamiApps, CVE-2025-14741

CVE, Research URL

CVE-2025-14741

Published on
Jan 09, 2026
Research Description
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modification and deletion due to a missing capability check on the 'delete_object' function in all versions up to, and including, 3.28.25. This makes it possible for unauthenticated attackers to delete arbitrary posts, pages, products, taxonomy terms, and user accounts.
Affected versions
max 3.28.26.
Status
vulnerable