
Proof-of-concept and disclosure pack for CVE-2026-19952, an unauthenticated arbitrary file deletion in the WordPress Frontend Admin plugin, with lab reproduction steps.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · [email protected] · CVE-2026-19952
Frontend Admin by DynamiApps 3.29.12 - DynamiApps
I am @abraxas_null. Loopback lab. The client is CVE-2026-19952-Abraxas-Labs.py.
The title is the path. Unauthenticated move_folders on acf/pre_update_value/type=upload_files (gallery), not upload_file. Merge tag [acf:post_title] takes the submitted title. Path is uploads basedir plus that name with no containment. unlink(upload_dir/index.php) when secure_directory is off. 3.29.13 adds get_safe_upload_dir.
| CVE | CVE-2026-19952 · CVE.org |
| CWE | CWE-22 |
| CVSS | High: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| Product | WordPress - Frontend Admin by DynamiApps |
| Affected | all versions through 3.29.12 (inclusive) |
| Patched | 3.29.13 and later |
| Auth | none |
| License | GNU Affero GPL v3.0 |
| Lab | 127.0.0.1 only |
Guest POST a new post whose title is ../somewhere. The plugin deletes somewhere/index.php. Delete the right file and you are in RCE territory. The lab deletes a planted witness file, not wp-config.php.
Wordfence named move_folders. I read the upload_files hook, then the merge tag, then planted a lab index.php.
Witness, harvest, POST, witness. GET /wp-content/poc19952/index.php must contain the string. GET /fea-files-lab/ for hiddens. POST title ../poc19952 and files 1. GET the index again. The string must be gone.
Wrong turns: action=move_folders or type upload_file (the hook is upload_files); [post:title] on new_post (id is still add_post, that tag bails; [acf:post_title] reads the submitted title); empty files field (if ( ! $value ) return); success JSON alone; deleting wp-config.php.
Port 8088. Frontend Admin 3.29.12. Planted /wp-content/poc19952/index.php. Public form /fea-files-lab/.
Target only 127.0.0.1:8088 (or the loopback you bound).
cd lab
docker compose up --force-recreate
python3 ../CVE-2026-19952-Abraxas-Labs.py
Witness: Before POST, GET /wp-content/poc19952/index.php contains POCWitness19952. After POST that string is gone (404/301). Form JSON success alone is not it.
Ways to lose without learning anything:
POCWitness19952 still present after POSTwp-config.phpUpdate Frontend Admin by DynamiApps to 3.29.13 or newer (get_safe_upload_dir). Re-run CVE-2026-19952-Abraxas-Labs.py against the patched build: the witness file must survive.
www.wordfence.com/threat-intel/vulnerabilities/id/55ec5101-6494-4180-9492-03863e839ad2?source=cve
Plugin directory: acf-frontend-form-element
Trac browser: plugins.trac.wordpress.org/acf-frontend-form-element
SVN tags: plugins.svn.wordpress.org/acf-frontend-form-element
Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null
GNU Affero GPL v3.0. See LICENSE.
The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.