PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106029 WeddingCity Lite CVE debrief

The WeddingCity Lite WordPress plugin through 1.0.4 does not perform any authorisation or validity checks before deleting posts, pages and media attachments, allowing unauthenticated attackers to permanently delete arbitrary content site-wide. This vulnerability affects WordPress installations with the WeddingCity Lite plugin, particularly those with publicly accessible content management interfaces. Defenders should assess exposure and prioritize remediation to prevent potential data loss and content manipulation.

Vendor
WeddingCity Lite
Product
WeddingCity Lite WordPress plugin
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

WordPress administrators, security teams, and developers who use or manage WordPress installations with the WeddingCity Lite plugin should assess exposure and prioritize remediation.

Why it matters

Defenders should care about CVE-2026-106029 because it allows unauthenticated attackers to permanently delete arbitrary content site-wide, potentially leading to data loss and content manipulation. WordPress administrators and security teams should assess exposure and prioritize remediation, especially for publicly accessible content management interfaces.

  • Potential for unauthorized content deletion
  • Need for additional authorization and validation checks
  • Risk of data loss and content manipulation

Technical summary

The WeddingCity Lite WordPress plugin through 1.0.4 is vulnerable to unauthorized content deletion due to a lack of authorisation and validity checks. Unauthenticated attackers can exploit this vulnerability to permanently delete posts, pages, and media attachments site-wide. To mitigate this vulnerability, defenders should verify the plugin version, implement additional authorization and validation checks for content deletion, and monitor for unauthorized content deletion attempts.

Defensive priority

Defenders should prioritize verifying and remediating this vulnerability, especially for WordPress installations with publicly accessible content management interfaces.

Recommended defensive actions

  • Verify the WeddingCity Lite WordPress plugin version and ensure it is not vulnerable
  • Implement additional authorization and validation checks for content deletion
  • Monitor for unauthorized content deletion attempts

Evidence notes

The CVE description and source reference indicate that the WeddingCity Lite WordPress plugin is vulnerable to unauthorized content deletion. However, details about affected versions, exploitation, and remediation are limited.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106029 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106029

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106029 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106029

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.