The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.25. This is due to insufficient validation of user-supplied role values in the validate_value, pre_update_value, and get_fields_display functions. This makes it possible for unauthenticated attackers to register as administrators and gain complete control of the site, granted they can access a user registration form containing a Role field.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.