CVE-2024-3729
Last modified
CVE-2024-3729 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'fea_encrypt' function in all versions up to, and including, 3.19.4. This makes it possible for unauthenticated attackers to manipulate the user processing forms, which can be used to add and edit administrator user for privilege escalation, or to automatically log in users for authentication bypass, or manipulate the post processing form that can be used to inject arbitrary web scripts. EPSS estimates a 0.81% chance of exploitation in the next 30 days.
Description
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'fea_encrypt' function in all versions up to, and including, 3.19.4. This makes it possible for unauthenticated attackers to manipulate the user processing forms, which can be used to add and edit administrator user for privilege escalation, or to automatically log in users for authentication bypass, or manipulate the post processing form that can be used to inject arbitrary web scripts. This can only be exploited if the 'openssl' php extension is not loaded on the server.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dynamiapps | Frontend Admin | < 3.19.5 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-3729?
How severe is CVE-2024-3729?
How do I fix CVE-2024-3729?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-37284Improper handling of alternate encoding occurs when Elastic …5.5
- CVE-2024-37285A deserialization issue in Kibana can lead to arbitrary code…7.2
- CVE-2024-37286APM server logs contain document body from a partially faile…6.5
- CVE-2024-37287A flaw allowing arbitrary code execution was discovered in K…7.2
- CVE-2024-37288A deserialization issue in Kibana can lead to arbitrary code…8.8
- CVE-2024-37289An improper access control vulnerability in Trend Micro Apex…7.8
- CVE-2024-37293The AWS Deployment Framework (ADF) is a framework to manage …7.8
- CVE-2024-37294Aimeos is an Open Source e-commerce framework for online sho…5.5
- CVE-2024-37295Aimeos is an Open Source e-commerce framework for online sho…7.2
- CVE-2024-37296The Aimeos HTML client provides Aimeos HTML components for e…5.3
- CVE-2024-37297WooCommerce is an open-source e-commerce platform built on W…5.4
- CVE-2024-37298gorilla/schema converts structs to and from form values. Pri…7.5
Are you affected by CVE-2024-3729?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
