
PoC for CVE-2025-13342
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to, and including, 3.28.20. This allows attackers to register users and set the default role to administrator. Exploitation becomes unauthenticated if a form created through Frontend Admin is publicly accessible (no login required). This is tested on Frontend Admin version 3.28.18.
Original vulnerability discoverer is YC_Infosec

Exploit requirements:
The release of this PoC is for research and educational purpose only. No further improvements will be done and is released as is. The author and researcher is not responsible for any damages due to exploitation of the unpatched wordpress plugin.