WordPress Plugin Vulnerabilities
Frontend Admin by DynamiApps < 3.29.13 - Unauthenticated .htaccess and index.php Deletion via Custom Directory Path Traversal
Description
The plugin does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files outside the intended directory, including the WordPress root, which can render the site inoperable. Successful exploitation requires a non-default form configuration.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
FILE DELETION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
RIA Labs
Submitter
RIA Labs
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-02 (about 19 hours ago)
Added
2026-09-02 (about 5 hours ago)
Last Updated
2026-09-02 (about 5 hours ago)