PT-2026-28193 · Dynamiapps+1 · Frontend Admin+1

CVE-2026-3328

·

Publicado

2026-03-26

·

Atualizado

2026-03-26

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Frontend Admin by DynamiApps plugin for WordPress versions prior to 3.28.32
Description The Frontend Admin by DynamiApps plugin for WordPress is susceptible to PHP Object Injection through the deserialization of the post content within admin form posts. This is a result of utilizing WordPress's maybe unserialize() function without implementing class restrictions on user-controllable content stored in the admin form post content. This allows authenticated attackers with Editor-level access or higher to inject a PHP Object. The presence of a PHP Object Payload (POP) chain enables attackers to achieve remote code execution.
Recommendations Update the Frontend Admin by DynamiApps plugin to version 3.28.32 or later.

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3328

Produtos afetados

Frontend Admin
Wordpress