Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Frontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_id' Parameter
Vulnerability Description
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the check to be skipped entirely when `$user_id` is a non-numeric string — a condition that can be induced by passing a crafted value such as `1one` through the unvalidated `item_id` parameter of the unauthenticated `wp_ajax_nopriv_frontend_admin/forms/change_form` AJAX endpoint. This makes it possible for attackers to escalate privileges to administrator by obtaining a server-signed `_acf_objects` payload carrying the non-numeric user ID, which WordPress subsequently coerces to integer 1 (the default administrator), allowing the attacker to overwrite that account's password or email address. Exploitation by unauthenticated users requires a public-facing frontend user form to be configured; in all other cases a subscriber-level account is sufficient.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
特权管理不恰当
Vulnerability Title
WordPress Frontend Admin by DynamiApps 权限许可和访问控制问题漏洞
Vulnerability Description
WordPress Frontend Admin by DynamiApps是WordPress基金会开源的一款允许用户在网站前端管理后台内容的CMS插件。 WordPress Frontend Admin by DynamiApps 3.29.9及之前版本存在权限许可和访问控制问题漏洞,该漏洞源于ActionUser::conditions_logic()函数将授权检查置于is_numeric()测试之后,导致当$user_id为非数字字符串时检查被跳过,攻击者可通过未验证的item_id参数传递特制值
CVSS Information
N/A
Vulnerability Type
N/A