{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/frontend-admin--3.29.12/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:dynamiapps:frontend_admin:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-19952"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Frontend Admin (\u003c= 3.29.12)"],"_cs_severities":["high"],"_cs_tags":["wordpress","arbitrary-file-deletion","remote-code-execution","cve-2026-19952"],"_cs_type":"advisory","_cs_vendors":["DynamiApps"],"content_html":"\u003cp\u003eThe Frontend Admin by DynamiApps plugin for WordPress, in versions up to and including 3.29.12, contains a critical security flaw in the 'move_folders' function. The vulnerability arises from insufficient validation of file paths, which permits an attacker to delete arbitrary files on the underlying server.\u003c/p\u003e\n\u003cp\u003eThis flaw is particularly dangerous because it is exploitable by unauthenticated users when a form is configured with public visibility settings (who_can_see='all'). In such cases, the nonce required to perform the action is exposed within the rendered form, allowing attackers to bypass standard authorization checks. Successful exploitation involves sending a crafted request to the plugin's endpoint, which, if successful, can lead to the deletion of sensitive files such as 'wp-config.php'. The removal of such core configuration files can trigger re-installation flows or expose database credentials, ultimately enabling an attacker to gain remote code execution or complete system compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a severe risk to WordPress installations utilizing the Frontend Admin plugin. If exploited, an attacker can delete arbitrary files, leading to site defacement, service disruption, or total system compromise via remote code execution. The exploit is accessible to unauthenticated remote attackers, making it a high-priority target for automated scanning and mass exploitation efforts.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Frontend Admin plugin to a version released after 3.29.12 immediately to incorporate necessary input validation patches.\u003c/li\u003e\n\u003cli\u003eAudit all forms configured within the Frontend Admin plugin and restrict visibility settings from 'all' to authenticated roles until the update is applied.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous POST requests targeting the plugin's path and 'move_folders' related parameters.\u003c/li\u003e\n\u003cli\u003eVerify file system integrity for critical WordPress files such as 'wp-config.php' and '.htaccess'.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T07:03:52Z","date_published":"2026-09-01T07:03:52Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-19952/","summary":"An unauthenticated arbitrary file deletion vulnerability in the Frontend Admin plugin for WordPress allows attackers to delete critical server files, potentially leading to remote code execution.","title":"Arbitrary File Deletion in Frontend Admin Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-19952/"}],"language":"en","title":"CraftedSignal Threat Feed - Frontend Admin (\u003c= 3.29.12)","version":"https://jsonfeed.org/version/1.1"}