CVE-2025-13342Active Exploitation

LOWCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to, and including, 3.28.20. This is due to insufficient capability checks and input validation in the ActionOptions::run() save handler. This makes it possible for unauthenticated attackers to modify critical WordPress options such as users_can_register, default_role, and admin_email via submitting crafted form data to public frontend forms.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-14); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-14: 1Mentions · 2026-08-14: 1Active Exploitation · 2026-04-14: 1Technical Details · 2026-04-14: 1Technical Details · 2026-08-14: 104-1408-14
Signal classification2 categories
Active Exploitation
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-141
Active Exploitation1
2026-08-141
Disclosure1
Full discourse2 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-13342 - critical 🚨 DynamiApps Frontend Admin <= 3.28.20 - Unauthenticated Arbitrary Options Update > DynamiApps Frontend Admin plugin for WordPress <.= 3.28.20 contains a broken access c... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-13342 @pdnuclei #Nu...

    Post summary

    The tweet announces a critical vulnerability (CVE-2025-13342) in DynamiApps Frontend Admin WordPress plugin versions <=3.28.20, describing an unauthenticated arbitrary options update flaw and pointing to a library page for more details.

    00001206
    1.2K followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2025-13342 Exploit in the wild confirmed for CVE-2025-13342 (CVSS null). The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modi... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    The post announces that CVE-2025-13342 is actively exploited in the wild, specifically targeting the Frontend Admin plugin for WordPress, but does not provide a PoC, exploit code, patch, or a false-positive claim.

    00000168
    5.6K followersView on X

Explore more