CVE-2026-104028 PUBLISHED

Anton Extensions <= 1.2.2 - Unauthenticated Arbitrary File Upload to RCE

Assigner: WPScan
Reserved: 01.10.2026 Published: 11.10.2026 Updated: 11.10.2026

The Anton Extensions WordPress plugin through 1.2.2 does not perform any capability check, nonce verification, or file-type validation before writing attacker-supplied content to an attacker-chosen path, allowing unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution.

Product Status

Vendor Unknown
Product Anton Extensions
Versions Default: unknown
  • affected from 0 to 1.2.2 (incl.)

Credits

  • Pablo González Pérez finder
  • Francisco José Ramírez Vicente and Iñigo Sánchez Enciso finder
  • WPScan coordinator

References

Problem Types

  • CWE-434 Unrestricted Upload of File with Dangerous Type CWE