CVE-2025-13342 is a critical missing-authorization vulnerability in the Frontend Admin by DynamiApps plugin for WordPress affecting all versions up to and including 3.28.20. The flaw is caused by insufficient capability checks and input validation in the ActionOptions::run() save handler, which processes option updates submitted through frontend forms. Because the handler does not properly verify that the requester is authorized to change WordPress configuration options, an unauthenticated attacker can submit crafted form data to publicly accessible frontend forms and modify arbitrary WordPress options. Reported examples of affected options include settings controlling user registration, default role assignment, and administrative contact email, creating a direct path to security-relevant site reconfiguration.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a standalone Python exploit for CVE-2025-13342 affecting the WordPress plugin Frontend Admin by DynamiApps <= 3.28.20. The repo is small and simple: one main exploit script (CVE-2025-13342.py), a README describing the vulnerability and usage, and a custom license. The Python script is the clear entry point and implements an interactive multithreaded exploitation workflow. Core capability: the exploit scans supplied target hosts for publicly accessible ACF frontend registration forms on a hardcoded list of common registration-related paths, parses form metadata such as hidden ACF fields, maps user-related fields, and submits a crafted POST request to the WordPress AJAX endpoint /wp-admin/admin-ajax.php using the action frontend_admin/form_submit. Its stated goal is to create a new administrator account without authentication by injecting role=administrator into the submitted user fields. The script uses fixed credentials embedded in code: username Nxadmin1, email nxploitedtest@gmail.com, and password NxAdmin_1337#KSA. Successful exploitation results are written to acf_success.txt. Repository structure and behavior: the script uses requests for HTTP interactions, BeautifulSoup for HTML parsing, ThreadPoolExecutor for concurrent processing of multiple targets, and rich/colorama for terminal UI. It prompts the operator for a targets file, worker count, timeout, and verbosity. It normalizes target URLs, probes multiple candidate registration endpoints, and then attempts exploitation per target in worker threads. This is not a detection-only utility; it is an operational exploit intended to achieve unauthorized admin account creation on vulnerable WordPress sites.
This repository contains a proof-of-concept (PoC) exploit for CVE-2025-13342, targeting the Frontend Admin by DynamiApps WordPress plugin (versions up to 3.28.20). The exploit is implemented in a single Python script (poc.py) and is accompanied by a README.md that explains the vulnerability and usage. The exploit works by first checking the plugin version via a direct HTTP request to the plugin's readme.txt file. It then scrapes a publicly accessible form created by the plugin to extract required nonce and form ID values. Finally, it sends a crafted POST request to the /wp-admin/admin-ajax.php endpoint, enabling user registration and setting the default role to administrator. This allows an attacker to register a new admin account without authentication, provided a vulnerable form is publicly accessible. The code is a functional PoC and does not include advanced payloads or automation for account registration, but demonstrates the core vulnerability and exploitation steps.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The content only indicates a conversation/update about CVE-2025-13342 and a description clarification; no technical details about the vulnerability are provided.
An unauthenticated arbitrary options update vulnerability in the same plugin, mentioned as part of the vendor's prior security history.
A prior vulnerability in the same plugin that allowed unauthenticated attackers to modify critical WordPress options.
A critical unauthenticated arbitrary options update vulnerability in the Frontend Admin by DynamiApps WordPress plugin (<= 3.28.20) allows remote attackers to modify sensitive WordPress options, potentially compromising site security and control.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.