PT-2026-84108 · Dynamiapps · Frontend Admin
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Frontend Admin by DynamiApps versions prior to 3.29.13
Description
Insufficient file path validation in the
move folders() function allows unauthenticated attackers to delete arbitrary files on the server. This issue is exploitable when a form is configured with public visibility (who can see='all'), as the required nonce is publicly obtainable from the rendered form. Deleting critical files, such as wp-config.php, can lead to remote code execution.Recommendations
Update the plugin to version 3.29.13 or later.
Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Frontend Admin