Descripción
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'fea_encrypt' function in all versions up to, and including, 3.19.4. This makes it possible unauthenticated attackers manipulate user processing forms, which can be used add edit administrator privilege escalation, or automatically log users authentication bypass, post form that inject arbitrary web scripts. only exploited if 'openssl' php extension not loaded server.
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.18.15/main/helpers.php#L617
https://plugins.trac.wordpress.org/changeset/3073379/acf-frontend-form-element#file4
https://www.wordfence.com/threat-intel/vulnerabilities/id/a2d22c5d-5ef5-4920-a1b5-e8284394c7e8?source=cve
https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.18.15/main/helpers.php#L617
https://plugins.trac.wordpress.org/changeset/3073379/acf-frontend-form-element#file4
https://www.wordfence.com/threat-intel/vulnerabilities/id/a2d22c5d-5ef5-4920-a1b5-e8284394c7e8?source=cve