PatchSiren cyber security CVE debrief
CVE-2026-104028 Anton Extensions CVE debrief
The Anton Extensions WordPress plugin through 1.2.2 is vulnerable to unauthenticated arbitrary PHP file uploads, potentially leading to remote code execution. This vulnerability allows attackers to upload and execute malicious PHP files, which can result in full control of the affected WordPress installation. Defenders should prioritize verifying exposure of WordPress installations using the Anton Extensions plugin, checking for unauthorized file uploads, and ensuring timely updates or patches.
- Vendor
- Anton Extensions
- Product
- Anton Extensions WordPress plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders responsible for WordPress installations using the Anton Extensions plugin should assess exposure and prioritize verification and patching. This includes security teams, WordPress administrators, and developers maintaining WordPress sites with the vulnerable plugin.
Why it matters
CVE-2026-104028 is a critical vulnerability in the Anton Extensions WordPress plugin that allows unauthenticated attackers to upload arbitrary PHP files, potentially leading to remote code execution. Defenders should prioritize verifying exposure, checking for unauthorized file uploads, and ensuring timely updates or patches to prevent exploitation.
- Potential remote code execution by unauthenticated attackers
- Possible unauthorized file uploads and modifications
- Required verification of WordPress installations and plugin versions
- Necessity for timely updates or patches to prevent exploitation
Technical summary
The Anton Extensions WordPress plugin through 1.2.2 does not perform any capability check, nonce verification, or file-type validation before writing attacker-supplied content to an attacker-chosen path. This vulnerability allows unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution. The plugin's failure to implement basic security measures enables attackers to execute malicious code, potentially leading to full control of the affected WordPress installation. Defenders should prioritize verifying exposure, checking for unauthorized file uploads, and ensuring timely updates or patches to prevent exploitation.
Defensive priority
Defenders should prioritize verifying exposure of WordPress installations using the Anton Extensions plugin, checking for unauthorized file uploads, and ensuring timely updates or patches.
Recommended defensive actions
- Verify WordPress installations for the Anton Extensions plugin and assess exposure
- Check for unauthorized file uploads and monitor for suspicious activity
- Ensure timely updates or patches for the Anton Extensions plugin
- Implement additional security measures, such as Web Application Firewall (WAF) rules, to detect and prevent exploitation
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
Evidence from the CVE Program and NVD indicates that the Anton Extensions WordPress plugin is vulnerable to unauthenticated arbitrary PHP file uploads, potentially leading to remote code execution. The vulnerability is confirmed in plugin version 1.2.2 and may affect earlier versions. Defenders should verify the presence of this plugin in their WordPress installations and check for signs of unauthorized file uploads. The CVE Program and NVD provide official records of this vulnerability, which should be consulted for further details.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104028 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104028
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104028 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104028
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/0be8a03e-d854-48db-bdc0-1beead3d7b91/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.