CVE-2026-104028
Anton Extensions <= 1.2.2 - Unauthenticated Arbitrary File Upload to RCE
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Anton Extensions WordPress plugin through 1.2.2 does not perform any capability check, nonce verification, or file-type validation before writing attacker-supplied content to an attacker-chosen path, allowing unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution.
| Vendor | unknown |
| Product | anton extensions |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown anton extensions
Be the first to know when new unknown vulnerabilities affecting unknown anton extensions are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / Anton Extensions
0 ≤ 1.2.2
References
Credits
Pablo González Pérez Francisco José Ramírez Vicente and Iñigo Sánchez Enciso WPScan