Sceawere

Vulnerability Detail

CVE-2026-106029UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Arbitrary Content Deletion

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
8h ago
Vendor
Unknown
Product
WeddingCity Lite
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

The WeddingCity Lite WordPress plugin through 1.0.4 does not perform any authorisation or validity checks before deleting posts, pages and media attachments, allowing unauthenticated attackers to permanently delete arbitrary content site-wide.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-11T07:17:22.963Z",
  "pubdate": "2026-10-11T07:17:22.963Z",
  "executiveSummary": "The WeddingCity Lite WordPress plugin, up to version 1.0.4, contains a critical security vulnerability classified as an Improper Authorization flaw. This vulnerability permits unauthenticated remote attackers to trigger the permanent deletion of arbitrary posts, pages, and media attachments across the entire WordPress installation.\nThe core issue stems from the plugin's failure to implement nonce verification or user capability checks within its post-deletion functions. Consequently, the application processes deletion requests without confirming the identity or authorization level of the requester.\nThe risk implication is severe, as successful exploitation facilitates a total denial-of-service (DoS) condition at the data layer, resulting in permanent loss of site content and media assets. No specialized privileges are required to conduct this attack, as the vulnerable endpoint remains exposed to anonymous users. The exploitability is high, requiring only that an attacker construct and submit a specifically crafted request to the vulnerable plugin component. Organizations utilizing WeddingCity Lite are at significant risk of site-wide data destruction until the vulnerability is addressed.",
  "technicalDetails": "The vulnerability resides within the backend processing logic of the WeddingCity Lite plugin, specifically where it handles content management operations. The root cause is the total absence of access control mechanisms—specifically, a lack of 'current_user_can()' capability checks and mandatory CSRF protection via WordPress nonces—prior to invoking deletion routines.\nIn the WordPress ecosystem, functions responsible for deleting content (e.g., 'wp_delete_post()' or 'wp_delete_attachment()') must be strictly guarded. The WeddingCity Lite plugin exposes an endpoint that improperly maps user-supplied input parameters directly to these deletion functions. Because the plugin does not validate the requester's session or permissions, any unauthenticated HTTP request directed at this endpoint is processed with the authority of the application server.\nThe attack flow proceeds as follows: First, an attacker identifies the specific URL or action hook used by the plugin for content management tasks. Second, the attacker crafts a malicious HTTP GET or POST request containing the unique 'ID' of the target post, page, or media object. Third, the attacker transmits this payload to the server. Upon receipt, the plugin's vulnerable function executes the deletion routine immediately without verifying if the user has 'delete_posts' or equivalent administrative capabilities.\nThis vulnerability is particularly dangerous because the underlying WordPress API functions permanently purge the content from the database and, in the case of media, remove the associated files from the server's filesystem. There is no requirement for the attacker to authenticate, bypass complex login screens, or perform any reconnaissance regarding user accounts. The exposure is entirely network-based, meaning any remote actor with access to the web server can trigger these destructive actions.\nThe post-exploitation impact is catastrophic from an availability perspective. By systematically iterating through post or media IDs, an attacker can effectively wipe a database of all its published and draft content. Given the nature of these WordPress functions, there is no built-in 'undo' mechanism for such administrative actions, meaning recovery is entirely dependent on the existence of a recent, functional off-site backup."
}
CVE-2026-106029: Unauthenticated Arbitrary Content Deletion (HIGH Severity, CVSS: 7.5) | Sceawere