CVE-2026-81347: Frontend Admin by DynamiApps < 3.29.13 - Unauthenticated .htaccess and index.php Deletion via Custom Directory Path Traversal
The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files outside the intended directory, including the WordPress root, which can render the site inoperable. Successful exploitation requires a non-default form configuration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Frontend Admin by DynamiAppsto a version that resolves this vulnerability.Fixed in 3.29.13
Event History
Frequently Asked Questions
Are sites using the plugin vulnerable with its default form configuration?
Successful exploitation requires a non-default form configuration. The provided information does not indicate that the default configuration is exploitable.
What access does an attacker need to exploit this issue?
An attacker can exploit the issue without authentication, provided the required non-default form configuration is present.
What is the likely impact if exploitation succeeds?
An attacker can delete index.php and .htaccess files outside the intended directory, including in the WordPress root. This can render the affected site inoperable.