Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

FluxContactConfidentialité© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
Outils/GitHubGitHub/abraxas/cve-2026-19952
Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingPapers & ResearchLabs & Practice
GitHubabraxas/cve-2026-19952

CVE-2026-19952

Proof-of-concept and disclosure pack for CVE-2026-19952, an unauthenticated arbitrary file deletion in the WordPress Frontend Admin plugin, with lab reproduction steps.

Voir le dépôt
16il y a 3 joursPas encore vérifié

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
Contenu non disponible dans la langue demandée. Affichage de la version anglaise.

Abraxas Labs - CVE-2026-19952

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-19952

CVE-2026-19952

Frontend Admin by DynamiApps 3.29.12 - DynamiApps

I am @abraxas_null. Loopback lab. The client is CVE-2026-19952-Abraxas-Labs.py.

The title is the path. Unauthenticated move_folders on acf/pre_update_value/type=upload_files (gallery), not upload_file. Merge tag [acf:post_title] takes the submitted title. Path is uploads basedir plus that name with no containment. unlink(upload_dir/index.php) when secure_directory is off. 3.29.13 adds get_safe_upload_dir.

CVECVE-2026-19952 · CVE.org
CWECWE-22
CVSSHigh: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
ProductWordPress - Frontend Admin by DynamiApps
Affectedall versions through 3.29.12 (inclusive)
Patched3.29.13 and later
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Guest POST a new post whose title is ../somewhere. The plugin deletes somewhere/index.php. Delete the right file and you are in RCE territory. The lab deletes a planted witness file, not wp-config.php.


How I found it

Wordfence named move_folders. I read the upload_files hook, then the merge tag, then planted a lab index.php.

Witness, harvest, POST, witness. GET /wp-content/poc19952/index.php must contain the string. GET /fea-files-lab/ for hiddens. POST title ../poc19952 and files 1. GET the index again. The string must be gone.

Wrong turns: action=move_folders or type upload_file (the hook is upload_files); [post:title] on new_post (id is still add_post, that tag bails; [acf:post_title] reads the submitted title); empty files field (if ( ! $value ) return); success JSON alone; deleting wp-config.php.


The lab

Port 8088. Frontend Admin 3.29.12. Planted /wp-content/poc19952/index.php. Public form /fea-files-lab/.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-19952-Abraxas-Labs.py

Witness: Before POST, GET /wp-content/poc19952/index.php contains POCWitness19952. After POST that string is gone (404/301). Form JSON success alone is not it.

Ways to lose without learning anything:

  • ajax success JSON without the file disappearing
  • POCWitness19952 still present after POST
  • deleting wp-config.php
  • reverse shell

The fix

Update Frontend Admin by DynamiApps to 3.29.13 or newer (get_safe_upload_dir). Re-run CVE-2026-19952-Abraxas-Labs.py against the patched build: the witness file must survive.


References

  • CVE-2026-19952 · NVD

  • CVE-2026-19952 · CVE.org

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/fields/general/class-upload-file.php#L1014

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/fields/general/class-upload-file.php#L1044

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/fields/general/class-upload-file.php#L1047

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/forms/classes/shortcodes.php#L99

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/forms/classes/submit.php#L125

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/forms/classes/submit.php#L276

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.13/main/frontend/fields/general/class-upload-file.php#L1047

  • www.wordfence.com/threat-intel/vulnerabilities/id/55ec5101-6494-4180-9492-03863e839ad2?source=cve

  • github.com/advisories/GHSA-3rrx-59q7-9g4m

  • nvd.nist.gov/vuln/detail/CVE-2026-19952

  • Plugin directory: acf-frontend-form-element

  • Trac browser: plugins.trac.wordpress.org/acf-frontend-form-element

  • SVN tags: plugins.svn.wordpress.org/acf-frontend-form-element

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

Télécharger l’outil