---
id: CVE-2026-81347
title: >-
  The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not
  properly validate a user-controllable directory path before deleting files
  within it, allowing unauthenticated attackers to delete index.php and
  .htaccess files ou…
summary: >-
  The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not
  properly validate a user-controllable directory path before deleting files
  within it, allowing unauthenticated attackers to delete index.php and
  .htaccess files ou…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-73
published: '2026-09-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:15:18.627'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81347'
references:
  - url: 'https://wpscan.com/vulnerability/61e54f2f-6d70-43fc-83a8-c47f8e29a3b3/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00381
epssPercentile: 0.29389
ingestedAt: '2026-09-08T20:10:03.163Z'
---

## Overview

The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files outside the intended directory, including the WordPress root, which can render the site inoperable. Successful exploitation requires a non-default form configuration.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
