CVE-2025-14741: critical vulnerability in shabti Frontend Admin by DynamiApps
Frontend Admin by DynamiApps <= 3.28.25 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via 'delete post' Form Element
Published · Updated
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.1epss 0.4%
exploitation probability
0.4%top 70% of all CVEs
observed exploitation
nono source reports it
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modification and deletion due to a missing capability check on the 'delete_object' function in all versions up to, and including, 3.28.25. This makes it possible for unauthenticated attackers to delete arbitrary posts, pages, products, taxonomy terms, and user accounts.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Affected products
shabti · Frontend Admin by DynamiAppsRelated CVEs — shabti Frontend Admin by DynamiApps
In the same product, most dangerous first.
CVE-2025-13342CRITICALFrontend Admin by DynamiApps <= 3.28.20 - Unauthenticated Arbitrary Options UpdateEPSS 2.2%CVE-2026-6226HIGHFrontend Admin by DynamiApps <= 3.29.2 - Unauthenticated Privilege Escalation via Form Configuration InjectionEPSS 1.2%CVE-2026-3328HIGHFrontend Admin by DynamiApps <= 3.28.31 - Authenticated (Editor+) PHP Object Injection via 'post_content' of Admin Form PostsEPSS 1.0%CVE-2026-19952HIGHFrontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Arbitrary File Deletion via Path Traversal via custom_directory_name Merge TagEPSS 1.0%CVE-2026-75816CRITICALFrontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_objects' Object IdentifierEPSS 0.9%CVE-2026-18432CRITICALFrontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_id' ParameterEPSS 0.8%