Sceawere
Vulnerability Detail
CVE-2026-104028UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Anton Extensions Arbitrary File Upload
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Anton Extensions
- Attack Type
- CWE-434 Unrestricted Upload of File with Dangerous Type
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Anton Extensions WordPress plugin through 1.2.2 does not perform any capability check, nonce verification, or file-type validation before writing attacker-supplied content to an attacker-chosen path, allowing unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-10-11T07:17:22.440Z",
"pubdate": "2026-10-11T07:17:22.440Z",
"executiveSummary": "The Anton Extensions WordPress plugin, specifically in versions up to 1.2.2, contains a critical security vulnerability categorized as an Unauthenticated Arbitrary File Upload. The flaw stems from a lack of mandatory access control mechanisms, including missing nonce verification and authorization checks, alongside a complete absence of server-side file type validation.\nThis vulnerability allows an unauthenticated remote attacker to inject arbitrary PHP code onto the host server. By bypassing standard security constraints, an attacker can designate the destination path for their malicious payloads, effectively gaining the capability to execute code within the context of the web server process. The successful exploitation of this flaw grants an attacker full Remote Code Execution (RCE) capabilities, enabling complete system compromise, data exfiltration, and unauthorized persistence within the WordPress environment.\nGiven that the exploit requires no authentication or administrative privileges, the risk profile for this vulnerability is extreme. It represents a direct path to full site takeover for any internet-facing installation utilizing the vulnerable plugin version.",
"technicalDetails": "The core vulnerability lies in the plugin's file handling logic, which fails to implement the WordPress best practices for secure file uploads. Specifically, the vulnerable component does not invoke current_user_can() or equivalent authorization functions to ensure that only authenticated administrators or privileged users can initiate file-writing operations. Furthermore, the absence of nonce verification (wp_verify_nonce) exposes the endpoint to Cross-Site Request Forgery (CSRF) and arbitrary POST requests from non-trusted origins.\nThe exploit flow begins with the attacker identifying the target endpoint responsible for processing file uploads within the Anton Extensions plugin. Because the implementation lacks input sanitization and file extension verification, the plugin indiscriminately writes user-supplied binary data—intended to be PHP scripts—directly into the filesystem. The attacker is not constrained by a whitelist of allowed MIME types or file extensions, permitting the upload of .php or other executable script files into web-accessible directories.\nOnce the payload is successfully written to an attacker-chosen path, the attacker triggers execution by making a direct HTTP GET request to the uploaded file's URI. Because the file is stored within the web root, the web server executes the malicious PHP instructions. The server-side environment interprets the attacker's code, granting the adversary the ability to interact with the underlying operating system, query the WordPress database, traverse the directory structure, or deploy web shells for long-term persistence.\nThe lack of architectural hardening here is total; there is no secondary validation, such as checking file headers, renaming files to mitigate extension spoofing, or storing uploads in a non-executable directory outside the public web root. As a result, the plugin acts as a bridge for remote attackers to execute arbitrary code with the same privileges as the web server user (e.g., www-data), leading to a complete compromise of the application's integrity, availability, and confidentiality."
}