Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 04 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dynamiapps
Dynamiapps frontend Admin By Dynamiapps Wordpress Wordpress wordpress |
|
| Vendors & Products |
Dynamiapps
Dynamiapps frontend Admin By Dynamiapps Wordpress Wordpress wordpress |
Fri, 04 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-73 | |
| Metrics |
cvssV3_1
|
Fri, 04 Sep 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 CWE-606 |
Fri, 04 Sep 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files outside the intended directory, including the WordPress root, which can render the site inoperable. Successful exploitation requires a non-default form configuration. | |
| Title | Frontend Admin by DynamiApps < 3.29.13 - Unauthenticated .htaccess and index.php Deletion via Custom Directory Path Traversal | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-04T12:48:34.897Z
Reserved: 2026-08-26T18:18:37.327Z
Link: CVE-2026-81347
Updated: 2026-09-04T12:48:29.781Z
Status : Received
Published: 2026-09-04T07:17:10.547
Modified: 2026-09-04T13:20:09.973
Link: CVE-2026-81347
No data.
OpenCVE Enrichment
Updated: 2026-09-04T14:15:07Z