CVE-2025-14741: Shabti Frontend Admin By Dynamiapps
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modification and deletion due to a missing capability check on the 'delete_object' function in all versions up to, and including, 3.28.25. This makes it possible for unauthenticated attackers to delete arbitrary posts, pages, products, taxonomy terms, and user accounts.
Affected products
- Shabti Frontend Admin By Dynamiapps: up to and including 3.28.25
Published 2026-01-09. Last modified 2026-06-17.