Frontend Admin plugin auth bypass allows WordPress account takeover
A CVSS 9.8 auth bypass in the Frontend Admin WordPress plugin allows unauthenticated account takeover in all versions through 3.29.12.
- Vendor
- DynamiApps
- Product
- Frontend Admin (acf-frontend-form-element)
- CVSS
- 9.8
- EPSS (exploit probability)
- 0.5%
- Status
- unpatched
- Published
The Frontend Admin plugin for WordPress, developed by DynamiApps and distributed as acf-frontend-form-element, contains an authentication bypass in the email field update handler (class-user-email.php). The pre_update_value hook does not properly verify account ownership, allowing an unauthenticated attacker to modify an account’s email address and take full control of that account.
All versions through 3.29.12 are affected. A patched version had not been confirmed at time of publication. Site operators should check the plugin’s WordPress.org changelog for a release newer than 3.29.12.
