PatchSiren cyber security CVE debrief
CVE-2026-106029 WeddingCity Lite CVE debrief
The WeddingCity Lite WordPress plugin through 1.0.4 does not perform any authorisation or validity checks before deleting posts, pages and media attachments, allowing unauthenticated attackers to permanently delete arbitrary content site-wide. This vulnerability affects WordPress installations with the WeddingCity Lite plugin, particularly those with publicly accessible content management interfaces. Defenders should assess exposure and prioritize remediation to prevent potential data loss and content manipulation.
- Vendor
- WeddingCity Lite
- Product
- WeddingCity Lite WordPress plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
WordPress administrators, security teams, and developers who use or manage WordPress installations with the WeddingCity Lite plugin should assess exposure and prioritize remediation.
Why it matters
Defenders should care about CVE-2026-106029 because it allows unauthenticated attackers to permanently delete arbitrary content site-wide, potentially leading to data loss and content manipulation. WordPress administrators and security teams should assess exposure and prioritize remediation, especially for publicly accessible content management interfaces.
- Potential for unauthorized content deletion
- Need for additional authorization and validation checks
- Risk of data loss and content manipulation
Technical summary
The WeddingCity Lite WordPress plugin through 1.0.4 is vulnerable to unauthorized content deletion due to a lack of authorisation and validity checks. Unauthenticated attackers can exploit this vulnerability to permanently delete posts, pages, and media attachments site-wide. To mitigate this vulnerability, defenders should verify the plugin version, implement additional authorization and validation checks for content deletion, and monitor for unauthorized content deletion attempts.
Defensive priority
Defenders should prioritize verifying and remediating this vulnerability, especially for WordPress installations with publicly accessible content management interfaces.
Recommended defensive actions
- Verify the WeddingCity Lite WordPress plugin version and ensure it is not vulnerable
- Implement additional authorization and validation checks for content deletion
- Monitor for unauthorized content deletion attempts
Evidence notes
The CVE description and source reference indicate that the WeddingCity Lite WordPress plugin is vulnerable to unauthorized content deletion. However, details about affected versions, exploitation, and remediation are limited.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106029 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106029
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106029 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106029
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/7a08e8fd-9795-4aac-b023-5e75b741400b/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.