WordPress Plugin Vulnerabilities

Frontend Admin by DynamiApps < 3.29.13 - Unauthenticated .htaccess and index.php Deletion via Custom Directory Path Traversal

Description

The plugin does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files outside the intended directory, including the WordPress root, which can render the site inoperable. Successful exploitation requires a non-default form configuration.

Proof of Concept

Affects Plugins

References

Classification

Type
FILE DELETION
CWE
CVSS

Miscellaneous

Original Researcher
RIA Labs
Submitter
RIA Labs
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-02 (about 19 hours ago)
Added
2026-09-02 (about 5 hours ago)
Last Updated
2026-09-02 (about 5 hours ago)

Other