Vulnerability Details CVE-2024-11720
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via submission forms in all versions up to, and including, 3.24.5 due to insufficient input sanitization and output escaping on the new Taxonomy form. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when lower-level users have been granted access to submit specific forms, which is disabled by default.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 39.4%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2024-11720
-
cpe:2.3:a:dynamiapps:frontend_admin:2.11.8
-
cpe:2.3:a:dynamiapps:frontend_admin:3.0.29
-
cpe:2.3:a:dynamiapps:frontend_admin:3.0.5
-
cpe:2.3:a:dynamiapps:frontend_admin:3.1.13
-
cpe:2.3:a:dynamiapps:frontend_admin:3.1.21
-
cpe:2.3:a:dynamiapps:frontend_admin:3.1.22
-
cpe:2.3:a:dynamiapps:frontend_admin:3.1.25
-
cpe:2.3:a:dynamiapps:frontend_admin:3.1.5
-
cpe:2.3:a:dynamiapps:frontend_admin:3.1.6
-
cpe:2.3:a:dynamiapps:frontend_admin:3.10.2
-
cpe:2.3:a:dynamiapps:frontend_admin:3.10.3
-
cpe:2.3:a:dynamiapps:frontend_admin:3.11.1
-
cpe:2.3:a:dynamiapps:frontend_admin:3.11.2
-
cpe:2.3:a:dynamiapps:frontend_admin:3.11.3
-
cpe:2.3:a:dynamiapps:frontend_admin:3.11.4
-
cpe:2.3:a:dynamiapps:frontend_admin:3.12.0
-
cpe:2.3:a:dynamiapps:frontend_admin:3.12.1
-
cpe:2.3:a:dynamiapps:frontend_admin:3.12.2
-
cpe:2.3:a:dynamiapps:frontend_admin:3.13.1
-
cpe:2.3:a:dynamiapps:frontend_admin:3.13.10
-
cpe:2.3:a:dynamiapps:frontend_admin:3.13.11
-
cpe:2.3:a:dynamiapps:frontend_admin:3.13.12
-
cpe:2.3:a:dynamiapps:frontend_admin:3.13.13
-
cpe:2.3:a:dynamiapps:frontend_admin:3.13.2
-
cpe:2.3:a:dynamiapps:frontend_admin:3.13.5
-
cpe:2.3:a:dynamiapps:frontend_admin:3.13.6
-
cpe:2.3:a:dynamiapps:frontend_admin:3.13.7
-
cpe:2.3:a:dynamiapps:frontend_admin:3.13.8
-
cpe:2.3:a:dynamiapps:frontend_admin:3.14.0
-
cpe:2.3:a:dynamiapps:frontend_admin:3.15.0
-
cpe:2.3:a:dynamiapps:frontend_admin:3.15.1
-
cpe:2.3:a:dynamiapps:frontend_admin:3.15.2
-
cpe:2.3:a:dynamiapps:frontend_admin:3.15.3
-
cpe:2.3:a:dynamiapps:frontend_admin:3.16.0
-
cpe:2.3:a:dynamiapps:frontend_admin:3.16.2
-
cpe:2.3:a:dynamiapps:frontend_admin:3.16.3
-
cpe:2.3:a:dynamiapps:frontend_admin:3.16.4
-
cpe:2.3:a:dynamiapps:frontend_admin:3.16.5
-
cpe:2.3:a:dynamiapps:frontend_admin:3.16.6
-
cpe:2.3:a:dynamiapps:frontend_admin:3.16.7
-
cpe:2.3:a:dynamiapps:frontend_admin:3.17.0
-
cpe:2.3:a:dynamiapps:frontend_admin:3.17.1
-
cpe:2.3:a:dynamiapps:frontend_admin:3.17.2
-
cpe:2.3:a:dynamiapps:frontend_admin:3.18.0
-
cpe:2.3:a:dynamiapps:frontend_admin:3.18.1
-
cpe:2.3:a:dynamiapps:frontend_admin:3.18.10
-
cpe:2.3:a:dynamiapps:frontend_admin:3.18.11
-
cpe:2.3:a:dynamiapps:frontend_admin:3.18.12
-
cpe:2.3:a:dynamiapps:frontend_admin:3.18.14
-
cpe:2.3:a:dynamiapps:frontend_admin:3.18.15
-
cpe:2.3:a:dynamiapps:frontend_admin:3.18.2
-
cpe:2.3:a:dynamiapps:frontend_admin:3.18.3
-
cpe:2.3:a:dynamiapps:frontend_admin:3.18.4
-
cpe:2.3:a:dynamiapps:frontend_admin:3.18.6
-
cpe:2.3:a:dynamiapps:frontend_admin:3.18.7
-
cpe:2.3:a:dynamiapps:frontend_admin:3.18.9
-
cpe:2.3:a:dynamiapps:frontend_admin:3.19.1
-
cpe:2.3:a:dynamiapps:frontend_admin:3.19.1.1
-
cpe:2.3:a:dynamiapps:frontend_admin:3.19.1.2
-
cpe:2.3:a:dynamiapps:frontend_admin:3.19.3
-
cpe:2.3:a:dynamiapps:frontend_admin:3.19.4
-
cpe:2.3:a:dynamiapps:frontend_admin:3.19.5
-
cpe:2.3:a:dynamiapps:frontend_admin:3.19.6
-
cpe:2.3:a:dynamiapps:frontend_admin:3.19.7
-
cpe:2.3:a:dynamiapps:frontend_admin:3.20.1
-
cpe:2.3:a:dynamiapps:frontend_admin:3.20.11
-
cpe:2.3:a:dynamiapps:frontend_admin:3.20.12
-
cpe:2.3:a:dynamiapps:frontend_admin:3.20.14
-
cpe:2.3:a:dynamiapps:frontend_admin:3.20.15
-
cpe:2.3:a:dynamiapps:frontend_admin:3.20.16
-
cpe:2.3:a:dynamiapps:frontend_admin:3.20.3
-
cpe:2.3:a:dynamiapps:frontend_admin:3.20.4
-
cpe:2.3:a:dynamiapps:frontend_admin:3.20.5
-
cpe:2.3:a:dynamiapps:frontend_admin:3.20.7
-
cpe:2.3:a:dynamiapps:frontend_admin:3.20.8
-
cpe:2.3:a:dynamiapps:frontend_admin:3.20.9
-
cpe:2.3:a:dynamiapps:frontend_admin:3.21.0
-
cpe:2.3:a:dynamiapps:frontend_admin:3.21.1
-
cpe:2.3:a:dynamiapps:frontend_admin:3.21.10
-
cpe:2.3:a:dynamiapps:frontend_admin:3.21.12
-
cpe:2.3:a:dynamiapps:frontend_admin:3.21.3
-
cpe:2.3:a:dynamiapps:frontend_admin:3.21.4
-
cpe:2.3:a:dynamiapps:frontend_admin:3.21.5
-
cpe:2.3:a:dynamiapps:frontend_admin:3.21.6
-
cpe:2.3:a:dynamiapps:frontend_admin:3.21.7
-
cpe:2.3:a:dynamiapps:frontend_admin:3.21.8
-
cpe:2.3:a:dynamiapps:frontend_admin:3.21.9
-
cpe:2.3:a:dynamiapps:frontend_admin:3.22.0
-
cpe:2.3:a:dynamiapps:frontend_admin:3.22.1
-
cpe:2.3:a:dynamiapps:frontend_admin:3.22.2
-
cpe:2.3:a:dynamiapps:frontend_admin:3.22.3
-
cpe:2.3:a:dynamiapps:frontend_admin:3.22.4
-
cpe:2.3:a:dynamiapps:frontend_admin:3.23.0
-
cpe:2.3:a:dynamiapps:frontend_admin:3.23.1
-
cpe:2.3:a:dynamiapps:frontend_admin:3.23.2
-
cpe:2.3:a:dynamiapps:frontend_admin:3.23.3
-
cpe:2.3:a:dynamiapps:frontend_admin:3.23.4
-
cpe:2.3:a:dynamiapps:frontend_admin:3.23.6
-
cpe:2.3:a:dynamiapps:frontend_admin:3.23.7
-
cpe:2.3:a:dynamiapps:frontend_admin:3.23.8
-
cpe:2.3:a:dynamiapps:frontend_admin:3.23.9
-
cpe:2.3:a:dynamiapps:frontend_admin:3.24.1
-
cpe:2.3:a:dynamiapps:frontend_admin:3.24.4
-
cpe:2.3:a:dynamiapps:frontend_admin:3.24.5
-
cpe:2.3:a:dynamiapps:frontend_admin:3.24.6
-
cpe:2.3:a:dynamiapps:frontend_admin:3.24.7
-
cpe:2.3:a:dynamiapps:frontend_admin:3.24.8
-
cpe:2.3:a:dynamiapps:frontend_admin:3.25.0
-
cpe:2.3:a:dynamiapps:frontend_admin:3.6.2
-
cpe:2.3:a:dynamiapps:frontend_admin:3.6.3
-
cpe:2.3:a:dynamiapps:frontend_admin:3.6.6
-
cpe:2.3:a:dynamiapps:frontend_admin:3.7.10
-
cpe:2.3:a:dynamiapps:frontend_admin:3.7.11
-
cpe:2.3:a:dynamiapps:frontend_admin:3.7.2
-
cpe:2.3:a:dynamiapps:frontend_admin:3.7.3
-
cpe:2.3:a:dynamiapps:frontend_admin:3.7.6
-
cpe:2.3:a:dynamiapps:frontend_admin:3.7.7
-
cpe:2.3:a:dynamiapps:frontend_admin:3.7.8
-
cpe:2.3:a:dynamiapps:frontend_admin:3.7.9
-
cpe:2.3:a:dynamiapps:frontend_admin:3.8.0
-
cpe:2.3:a:dynamiapps:frontend_admin:3.8.1
-
cpe:2.3:a:dynamiapps:frontend_admin:3.8.4
-
cpe:2.3:a:dynamiapps:frontend_admin:3.8.5
-
cpe:2.3:a:dynamiapps:frontend_admin:3.9.0
-
cpe:2.3:a:dynamiapps:frontend_admin:3.9.1
-
cpe:2.3:a:dynamiapps:frontend_admin:3.9.10
-
cpe:2.3:a:dynamiapps:frontend_admin:3.9.11
-
cpe:2.3:a:dynamiapps:frontend_admin:3.9.12
-
cpe:2.3:a:dynamiapps:frontend_admin:3.9.14
-
cpe:2.3:a:dynamiapps:frontend_admin:3.9.15
-
cpe:2.3:a:dynamiapps:frontend_admin:3.9.19
-
cpe:2.3:a:dynamiapps:frontend_admin:3.9.2
-
cpe:2.3:a:dynamiapps:frontend_admin:3.9.20
-
cpe:2.3:a:dynamiapps:frontend_admin:3.9.21
-
cpe:2.3:a:dynamiapps:frontend_admin:3.9.22
-
cpe:2.3:a:dynamiapps:frontend_admin:3.9.23
-
cpe:2.3:a:dynamiapps:frontend_admin:3.9.3
-
cpe:2.3:a:dynamiapps:frontend_admin:3.9.4
-
cpe:2.3:a:dynamiapps:frontend_admin:3.9.5
-
cpe:2.3:a:dynamiapps:frontend_admin:3.9.6
-
cpe:2.3:a:dynamiapps:frontend_admin:3.9.8
-
cpe:2.3:a:dynamiapps:frontend_admin:3.9.9