Arbitrary File Deletion Vulnerability in Frontend Admin Plugin for WordPress by DynamiApps
CVE-2026-19952

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 September 2026

What is CVE-2026-19952?

The Frontend Admin plugin by DynamiApps for WordPress is susceptible to arbitrary file deletion due to a lack of proper file path validation in the move_folders function. This vulnerability is present in all versions up to and including 3.29.12. Attackers, even without authentication, may exploit this flaw to delete any arbitrary files on the server, which can ultimately facilitate remote code execution if critical files such as wp-config.php are erased. This issue is particularly dangerous when forms are configured with public visibility, allowing attackers to obtain the necessary nonce from rendered forms.

Affected Version(s)

Frontend Admin by DynamiApps 0 <= 3.29.12

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nudien
.