CVE-2026-3328 identifies a high-severity PHP Object Injection vulnerability (CVSS 7.2) in the Frontend Admin by DynamiApps WordPress plugin, affecting versions up to 3.28.31. This flaw allows authenticated attackers with Editor-level privileges to achieve Remote Code Execution by exploiting insecure deserialization of user-controlled post content. The attack vector is network-based with low complexity, requiring high privileges for successful exploitation. Currently, there is no evidence of active exploitation, nor are public exploit codes or community discussions available, though the existence of a POP chain indicates a clear path to RCE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Shabti | Frontend Admin By DynamiApps | >= 0, <= 3.28.31CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.