
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14736 is a privilege escalation vulnerability in the Frontend Admin by DynamiApps plugin for WordPress, classified under CWE-269 (Improper Privilege Management). It affects all versions up to and including 3.28.29 (initially disclosed as affecting up to 3.28.25; updated by Wordfence on April 8, 2026). The flaw allows unauthenticated attackers to self-register as WordPress administrators by manipulating role values in user registration forms. It was published on January 9, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical), assigned by Wordfence (Wordfence, NVD).
The vulnerability stems from insufficient server-side validation of user-supplied role values within three functions in the plugin's role field handler (class-role.php): validate_value, pre_update_value, and get_fields_display. Because these functions do not enforce allowable role boundaries, an attacker can submit an arbitrary role value — including administrator — through a publicly accessible user registration form that includes a Role field (Wordfence, NVD). The attack requires no authentication and no user interaction, and exploitation complexity is low. A public proof-of-concept is available on GitHub (PoC GitHub). The patch is visible in the WordPress plugin repository changeset for class-role.php (Plugin Changeset).
Successful exploitation grants an unauthenticated attacker full administrative access to the WordPress site, resulting in complete compromise of confidentiality, integrity, and availability. An attacker with administrator privileges can install malicious plugins or themes, exfiltrate all site data (including user credentials and private content), deface the site, or use the compromised server as a pivot point for further attacks against the hosting environment or connected systems (Wordfence, NVD).
A proof-of-concept exploit was published on GitHub (added March 2, 2026) (PoC GitHub), and the exploit has also been indexed by Vulners. As of the latest available data, there is no confirmed evidence of active in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.04%, reflecting low but non-zero automated exploitation probability. The vulnerability is detected by Qualys (detection ID 530814) (Qualys).
administrator (or another privileged WordPress role) before submitting the request.validate_value, pre_update_value, and get_fields_display, the server accepts the attacker-supplied role.administrator role from unexpected IP addresses; entries in wp-login.php or registration endpoint access logs around or after January 9, 2026.wp_users and wp_usermeta tables where wp_capabilities contains administrator for recently created accounts with no legitimate business justification.Wordfence references a patch in the plugin repository changeset for class-role.php (changeset 3427243), and a second changeset (3472098) was added in April 2026, suggesting the fix was extended to cover versions up to 3.28.29 (Plugin Changeset, NVD). Site administrators should update the Frontend Admin by DynamiApps plugin to the latest available version immediately. If an update is not yet available or cannot be applied, disable or remove the plugin, and remove any Role field from public-facing registration forms as an interim workaround. Review all administrator accounts for unauthorized entries and audit recent user registrations. Wordfence firewall rules provide additional protection for sites running Wordfence (Wordfence).
Wordfence disclosed and assigned the CVE, publishing it in their weekly WordPress vulnerability report for January 5–11, 2026 (Wordfence Blog). The vulnerability was picked up by The Hacker Wire and shared on Mastodon and Bluesky, indicating moderate community awareness. Security aggregators including Vulners, VulDB, and Qualys indexed the vulnerability shortly after disclosure. No major vendor statements beyond Wordfence's advisory have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."