WordPress 的 DynamiApps Frontend Admin 插件存在任意文件删除漏洞,原因是 函数中对文件路径的校验不足,影响版本为 3.29.12 及更早版本。这使得未认证的攻击者可以删除服务器上的任意文件;当特定文件(如 )被删除时,极易导致远程代码执行(RCE)。若表单配置为公开可见(即 ),则无需认证即可利用该漏洞,因为所需的 nonce 值可从已渲染的表单中公开获取。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| shabti | Frontend Admin by DynamiApps | 0 ~ 3.29.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet