Sceawere
Vulnerability Detail
CVE-2026-6243UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Frontend Admin Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 3h ago
- Vendor
- shabti
- Product
- Frontend Admin by DynamiApps
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kses bypass / mutation XSS in all versions up to, and including, 3.28.36. This is due to the 'get_dynamic_values' function performing text-level find-and-replace operations on post content without HTML-aware parsing. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-10-10T07:16:41.783Z",
"pubdate": "2026-10-10T07:16:41.783Z",
"executiveSummary": "The Frontend Admin plugin for WordPress, up to version 3.28.36, contains a Stored Cross-Site Scripting (XSS) vulnerability. This security flaw originates from improper input sanitization and an insecure text-replacement implementation within the plugin's core functions. The vulnerability allows authenticated attackers, specifically those with Contributor-level access or higher, to inject malicious JavaScript payloads into post content.\nWhen a user with sufficient privileges views a compromised post, the injected script executes within the context of the user's browser session. This creates significant security risks, including the potential for unauthorized administrative actions, session hijacking, credential theft, or site defacement. The reliance on regex-based or text-level find-and-replace operations instead of robust, HTML-aware sanitization renders the site susceptible to mutation XSS attacks. Given that the exploitation only requires a Contributor-level account, the attack surface includes any WordPress installation where untrusted users are permitted to create or edit post content using the Frontend Admin plugin. There is no evidence of this vulnerability being mitigated by current WordPress core input filters, as the plugin bypasses these protections during the 'get_dynamic_values' processing routine.",
"technicalDetails": "The vulnerability resides within the 'get_dynamic_values' function of the Frontend Admin plugin. The root cause is the utilization of unsafe, text-level find-and-replace operations applied to post content. WordPress typically employs 'kses' (a library for sanitizing HTML) to strip potentially malicious markup; however, this plugin performs its own data manipulation after or alongside this process using non-HTML-aware logic. By leveraging this design flaw, an attacker can bypass traditional security filters using mutation XSS techniques.\nMutation XSS occurs when an attacker crafts input that appears benign to initial sanitization routines but is transformed into valid, executable JavaScript by the application’s subsequent text-processing operations or the browser's DOM parsing behavior. Because 'get_dynamic_values' treats post content as a simple string for replacement tasks, it fails to account for nested HTML entities, malformed tags, or attribute-based injection vectors that are otherwise neutralized by secure parsers.\nThe exploitation flow proceeds as follows: 1. An authenticated attacker with Contributor-level privileges or higher creates or edits a post using the Frontend Admin interface. 2. The attacker injects a specifically crafted payload containing malicious script tags or event handlers (e.g., onerror, onload) designed to survive or bypass the plugin’s regex filters. 3. The plugin saves this content to the database without secure sanitization. 4. When a victim, such as an administrator or another authorized user, accesses the frontend page where the 'get_dynamic_values' function is invoked, the malicious payload is rendered directly into the Document Object Model (DOM). 5. The browser interprets the injected string as executable code, triggering the script execution in the context of the victim's session.\nThis vulnerability is classified as Stored XSS because the payload is persisted within the application's database. The impact is severe, as the injected script inherits the privileges of the victim. If an administrator views the page, the attacker could theoretically perform arbitrary actions, such as creating new administrative accounts, modifying plugin settings, or injecting further malicious payloads into other areas of the site. The lack of context-aware parsing ensures that standard input-validation mechanisms are ineffective against this specific attack vector."
}