Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

الخلاصاتاتصالالخصوصية© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2026-19952 — Proof-of-concept and disclosure pack for CVE-2026-19952, an unauthenticated arbitrary file deletion in the WordPress Frontend Admin plugin, with lab reproduction steps. | Kitploit
أدوات/GitHubGitHub/abraxas/cve-2026-19952
Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingPapers & ResearchLabs & Practice
GitHubabraxas/cve-2026-19952

CVE-2026-19952

Proof-of-concept and disclosure pack for CVE-2026-19952, an unauthenticated arbitrary file deletion in the WordPress Frontend Admin plugin, with lab reproduction steps.

16منذ 3 أياملم تتم المراجعة بعد
عرض المستودع

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

Abraxas Labs - CVE-2026-19952

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-19952

CVE-2026-19952

Frontend Admin by DynamiApps 3.29.12 - DynamiApps

I am @abraxas_null. Loopback lab. The client is CVE-2026-19952-Abraxas-Labs.py.

The title is the path. Unauthenticated move_folders on acf/pre_update_value/type=upload_files (gallery), not upload_file. Merge tag [acf:post_title] takes the submitted title. Path is uploads basedir plus that name with no containment. unlink(upload_dir/index.php) when secure_directory is off. 3.29.13 adds get_safe_upload_dir.

CVECVE-2026-19952 · CVE.org
CWECWE-22
CVSSHigh: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
ProductWordPress - Frontend Admin by DynamiApps
Affectedall versions through 3.29.12 (inclusive)
Patched3.29.13 and later
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Guest POST a new post whose title is ../somewhere. The plugin deletes somewhere/index.php. Delete the right file and you are in RCE territory. The lab deletes a planted witness file, not wp-config.php.


How I found it

Wordfence named move_folders. I read the upload_files hook, then the merge tag, then planted a lab index.php.

Witness, harvest, POST, witness. GET /wp-content/poc19952/index.php must contain the string. GET /fea-files-lab/ for hiddens. POST title ../poc19952 and files 1. GET the index again. The string must be gone.

Wrong turns: action=move_folders or type upload_file (the hook is upload_files); [post:title] on new_post (id is still add_post, that tag bails; [acf:post_title] reads the submitted title); empty files field (if ( ! $value ) return); success JSON alone; deleting wp-config.php.


The lab

Port 8088. Frontend Admin 3.29.12. Planted /wp-content/poc19952/index.php. Public form /fea-files-lab/.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-19952-Abraxas-Labs.py

Witness: Before POST, GET /wp-content/poc19952/index.php contains POCWitness19952. After POST that string is gone (404/301). Form JSON success alone is not it.

Ways to lose without learning anything:

  • ajax success JSON without the file disappearing
  • POCWitness19952 still present after POST
  • deleting wp-config.php
  • reverse shell

The fix

Update Frontend Admin by DynamiApps to 3.29.13 or newer (get_safe_upload_dir). Re-run CVE-2026-19952-Abraxas-Labs.py against the patched build: the witness file must survive.


References

  • CVE-2026-19952 · NVD

  • CVE-2026-19952 · CVE.org

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/fields/general/class-upload-file.php#L1014

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/fields/general/class-upload-file.php#L1044

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/fields/general/class-upload-file.php#L1047

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/forms/classes/shortcodes.php#L99

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/forms/classes/submit.php#L125

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/forms/classes/submit.php#L276

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.13/main/frontend/fields/general/class-upload-file.php#L1047

  • www.wordfence.com/threat-intel/vulnerabilities/id/55ec5101-6494-4180-9492-03863e839ad2?source=cve

  • github.com/advisories/GHSA-3rrx-59q7-9g4m

  • nvd.nist.gov/vuln/detail/CVE-2026-19952

  • Plugin directory: acf-frontend-form-element

  • Trac browser: plugins.trac.wordpress.org/acf-frontend-form-element

  • SVN tags: plugins.svn.wordpress.org/acf-frontend-form-element

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

تنزيل الأداة