Unrated severityNVD Advisory· Published Sep 4, 2026
CVE-2026-81347
CVE-2026-81347
Description
The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files outside the intended directory, including the WordPress root, which can render the site inoperable. Successful exploitation requires a non-default form configuration.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.29.13
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.