CVE-2026-81347
Received Received - Intake

Frontend Admin WordPress Plugin Directory Traversal Vulnerability

Vulnerability report for CVE-2026-81347, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: WPScan

Description

The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files outside the intended directory, including the WordPress root, which can render the site inoperable. Successful exploitation requires a non-default form configuration.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
dynamiapps frontend_admin to 3.29.13 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Frontend Admin by DynamiApps WordPress plugin before version 3.29.13. It allows unauthenticated attackers to delete important files like index.php and .htaccess outside the intended directory, including the WordPress root directory. This happens because the plugin does not properly validate user-controlled directory paths before deleting files. Successful exploitation requires a non-default form configuration.

Detection Guidance

Check if the Frontend Admin by DynamiApps plugin version is below 3.29.13. Use WordPress admin panel or run a command like 'wp plugin list' if using WP-CLI to verify the installed version.

Impact Analysis

This vulnerability can make your website inoperable by deleting critical files such as index.php and .htaccess. This can disrupt access to your site and potentially cause data loss or downtime. Attackers do not need authentication to exploit this issue, increasing the risk of unauthorized actions.

Mitigation Strategies

Update the Frontend Admin by DynamiApps plugin to version 3.29.13 or later immediately. If updating is not possible, consider disabling the plugin until the update is applied to prevent potential exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81347. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart