VulnerAlert



APPS
WORDPRESS
05-06-2025 21:11

CVE-2024-3729 Vulnerabilidad documentada

Sin puntuación
Tags
#wordpress
#plugin
#exploit
#web
#ssl
#server
#php
#open
#form
#admin
#add
#apps
#/exploit(.*)php/iU
#exploit php
#improper
#attackers
#authenticated
#bypass
#arbitrary
#vulnerable
#privilege escalation
#privilege
#pass
#manipulate
#inject
#attack
Descripción
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'fea_encrypt' function in all versions up to, and including, 3.19.4. This makes it possible unauthenticated attackers manipulate user processing forms, which can be used add edit administrator privilege escalation, or automatically log users authentication bypass, post form that inject arbitrary web scripts. only exploited if 'openssl' php extension not loaded server.
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.18.15/main/helpers.php#L617
https://plugins.trac.wordpress.org/changeset/3073379/acf-frontend-form-element#file4
https://www.wordfence.com/threat-intel/vulnerabilities/id/a2d22c5d-5ef5-4920-a1b5-e8284394c7e8?source=cve
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.18.15/main/helpers.php#L617
https://plugins.trac.wordpress.org/changeset/3073379/acf-frontend-form-element#file4
https://www.wordfence.com/threat-intel/vulnerabilities/id/a2d22c5d-5ef5-4920-a1b5-e8284394c7e8?source=cve
Referencia
Link externo
Ver detalles

Fuente
https://nvd.nist.gov/vuln/detail/CVE-2024-3729
Resultados similares
Coincidentes en almenos en 50% de los tags
06-06-2025 CVE-2025-5733
The Modern Events Calendar Lite plugin for WordPress is vulnerable to Full Path Disclosure in a...
Ver información
06-06-2025 CVE-2025-5760
The Simple History plugin for WordPress is vulnerable to sensitive data exposure via Detective ...
Ver información
Icons made by Freepik from www.flaticon.com
Este Proyecto fue cofinanciado por el Consejo Nacional de Ciencia y Tecnología (CONACYT) a través del PROINNOVA 2021/2023
Proyecto realizado por