CVE-2025-14741 is a critical missing authorization vulnerability in the Frontend Admin by DynamiApps WordPress plugin, affecting all versions up to 3.28.25. This flaw allows unauthenticated attackers to delete arbitrary posts, pages, products, taxonomy terms, and user accounts due to a missing capability check. With a CVSS score of 9.1 (CRITICAL), it presents a high impact on integrity and availability, requiring no user interaction or authentication. There is currently no public exploit code (Metasploit, Nuclei, ExploitDB) and it is not listed in CISA's KEV catalog, though it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Shabti | Frontend Admin By DynamiApps | >= 0, <= 3.28.25CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.