Sceawere

Vulnerability Detail

CVE-2026-104028UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Anton Extensions Arbitrary File Upload

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
8h ago
Vendor
Unknown
Product
Anton Extensions
Attack Type
CWE-434 Unrestricted Upload of File with Dangerous Type
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Anton Extensions WordPress plugin through 1.2.2 does not perform any capability check, nonce verification, or file-type validation before writing attacker-supplied content to an attacker-chosen path, allowing unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-11T07:17:22.440Z",
  "pubdate": "2026-10-11T07:17:22.440Z",
  "executiveSummary": "The Anton Extensions WordPress plugin, specifically in versions up to 1.2.2, contains a critical security vulnerability categorized as an Unauthenticated Arbitrary File Upload. The flaw stems from a lack of mandatory access control mechanisms, including missing nonce verification and authorization checks, alongside a complete absence of server-side file type validation.\nThis vulnerability allows an unauthenticated remote attacker to inject arbitrary PHP code onto the host server. By bypassing standard security constraints, an attacker can designate the destination path for their malicious payloads, effectively gaining the capability to execute code within the context of the web server process. The successful exploitation of this flaw grants an attacker full Remote Code Execution (RCE) capabilities, enabling complete system compromise, data exfiltration, and unauthorized persistence within the WordPress environment.\nGiven that the exploit requires no authentication or administrative privileges, the risk profile for this vulnerability is extreme. It represents a direct path to full site takeover for any internet-facing installation utilizing the vulnerable plugin version.",
  "technicalDetails": "The core vulnerability lies in the plugin's file handling logic, which fails to implement the WordPress best practices for secure file uploads. Specifically, the vulnerable component does not invoke current_user_can() or equivalent authorization functions to ensure that only authenticated administrators or privileged users can initiate file-writing operations. Furthermore, the absence of nonce verification (wp_verify_nonce) exposes the endpoint to Cross-Site Request Forgery (CSRF) and arbitrary POST requests from non-trusted origins.\nThe exploit flow begins with the attacker identifying the target endpoint responsible for processing file uploads within the Anton Extensions plugin. Because the implementation lacks input sanitization and file extension verification, the plugin indiscriminately writes user-supplied binary data—intended to be PHP scripts—directly into the filesystem. The attacker is not constrained by a whitelist of allowed MIME types or file extensions, permitting the upload of .php or other executable script files into web-accessible directories.\nOnce the payload is successfully written to an attacker-chosen path, the attacker triggers execution by making a direct HTTP GET request to the uploaded file's URI. Because the file is stored within the web root, the web server executes the malicious PHP instructions. The server-side environment interprets the attacker's code, granting the adversary the ability to interact with the underlying operating system, query the WordPress database, traverse the directory structure, or deploy web shells for long-term persistence.\nThe lack of architectural hardening here is total; there is no secondary validation, such as checking file headers, renaming files to mitigate extension spoofing, or storing uploads in a non-executable directory outside the public web root. As a result, the plugin acts as a bridge for remote attackers to execute arbitrary code with the same privileges as the web server user (e.g., www-data), leading to a complete compromise of the application's integrity, availability, and confidentiality."
}
CVE-2026-104028: Anton Extensions Arbitrary File Upload (CRITICAL Severity, CVSS: 9.8) | Sceawere