Arbitrary File Deletion Vulnerability in Frontend Admin Plugin for WordPress by DynamiApps
CVE-2026-19952
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 September 2026
What is CVE-2026-19952?
The Frontend Admin plugin by DynamiApps for WordPress is susceptible to arbitrary file deletion due to a lack of proper file path validation in the move_folders function. This vulnerability is present in all versions up to and including 3.29.12. Attackers, even without authentication, may exploit this flaw to delete any arbitrary files on the server, which can ultimately facilitate remote code execution if critical files such as wp-config.php are erased. This issue is particularly dangerous when forms are configured with public visibility, allowing attackers to obtain the necessary nonce from rendered forms.
Affected Version(s)
Frontend Admin by DynamiApps 0 <= 3.29.12