Directory Traversal Vulnerability in Frontend Admin by DynamiApps
CVE-2026-81347
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 September 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-81347?
The Frontend Admin plugin for WordPress, developed by DynamiApps, has a vulnerability that allows unauthenticated attackers to exploit improper validation of user-controllable directory paths. This flaw permits the deletion of critical files such as index.php and .htaccess, which can severely disrupt WordPress site functionality. Such exploitation typically requires specific non-default configurations, exposing WordPress sites to potential inoperability.
Affected Version(s)
Frontend Admin by DynamiApps 0 < 3.29.13
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.