🔐 CVE Alert

CVE-2026-104028

UNKNOWN 0.0

Anton Extensions <= 1.2.2 - Unauthenticated Arbitrary File Upload to RCE

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Anton Extensions WordPress plugin through 1.2.2 does not perform any capability check, nonce verification, or file-type validation before writing attacker-supplied content to an attacker-chosen path, allowing unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution.

Vendor unknown
Product anton extensions
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown anton extensions

Be the first to know when new unknown vulnerabilities affecting unknown anton extensions are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / Anton Extensions
0 ≤ 1.2.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/0be8a03e-d854-48db-bdc0-1beead3d7b91/

Credits

Pablo González Pérez Francisco José Ramírez Vicente and Iñigo Sánchez Enciso WPScan