Vendor
high
advisory
Arbitrary File Deletion in Frontend Admin Plugin for WordPress
1 TTP 1 CVEAn unauthenticated arbitrary file deletion vulnerability in the Frontend Admin plugin for WordPress allows attackers to delete critical server files, potentially leading to remote code execution.
PoC
Frontend Admin +1
wordpress
arbitrary-file-deletion
remote-code-execution
cve-2026-19952
1t
1c
updated
critical
advisory
Privilege Escalation in Frontend Admin by DynamiApps Plugin for WordPress
1 rule 1 TTP 1 CVECVE-2026-18432 allows unauthenticated or subscriber-level attackers to escalate privileges to administrator via an improper authorization check in the Frontend Admin plugin for WordPress.
Frontend Admin by DynamiApps
1r
1t
1c
high
advisory
Authorization Bypass in Frontend Admin WordPress Plugin
1 TTP 1 CVEAuthenticated attackers can perform CBC bit-flipping attacks on the Frontend Admin plugin to reset arbitrary user passwords, enabling full site compromise.
Frontend Admin
1t
1c