CRITICAL
9.8 CVE-2026-104028 Published 11 Oct 2026
WordPress Anton Extensions Plugin Arbitrary File Upload RCE Vulnerability
Worried this affects your website?
The Anton Extensions WordPress plugin through 1.2.2 contains an arbitrary file upload vulnerability. Before writing attacker-supplied content to an attacker-chosen path, the plugin fails to perform several security checks:
- No capability check
- No nonce verification
- No file-type validation
As a result, unauthenticated attackers can upload arbitrary PHP files and achieve remote code execution.
Reference: CVE-2026-104028 on NVD
← Back to Security News