PatchSiren

Anton Extensions CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Anton Extensions CVE published 2026-10-11

CVE-2026-104028

The Anton Extensions WordPress plugin through 1.2.2 is vulnerable to unauthenticated arbitrary PHP file uploads, potentially leading to remote code execution. This vulnerability allows attackers to upload and execute malicious PHP files, which can result in full control of the affected WordPress installation. Defenders should prioritize verifying exposure of WordPress installations using the Anton Extensi [truncated]