vulnerability
Published 2026-10-11
Verified 2026-10-11

WPScan batch (11 Oct): Anton Extensions lets anyone upload PHP and take over the site, Mobile Builder has unauthenticated SQL injection and a customer-to-admin escalation, WeddingCity Lite lets anyone delete content (no fixes); Envira Gallery fixes four access bugs in 1.16.2

WPScan, acting as CVE numbering authority, published a batch of WordPress plugin CVEs on 11 October 2026. The most serious have no fixed release. CVE-2026-104028 in Anton Extensions (through 1.2.2) skips capability, nonce and file-type checks before writing attacker-supplied content to an attacker-chosen path, so an unauthenticated attacker can upload a PHP file and run code on the server. Mobile Builder (through 1.4.2) has two: CVE-2026-103695, an unauthenticated SQL injection through the vendor_id parameter, and CVE-2026-103694, a REST route that lets any self-registered user such as a customer update their own user meta and grant themselves the administrator role. CVE-2026-106029 in WeddingCity Lite (through 1.0.4) lets unauthenticated attackers permanently delete any post, page or media attachment, and CVE-2026-103305 in Prenotazioni (through 1.7.5) lets unauthenticated visitors change its settings and plant stored cross-site scripting that runs against administrators and visitors. Envira Gallery fixes four lower-impact access-control bugs in 1.16.2 (CVE-2026-104680 to CVE-2026-104684): on Multisite a subsite administrator could install other WordPress.org plugins through its setup wizard, and Author or Contributor accounts could expose private post titles and excerpts, publish gallery posts the settings withhold, or embed other users' non-public galleries. Dokan before 5.2.0 lets a vendor read the commission settings set for other vendors (CVE-2026-107694), and Squadeno before 1.12.0 lets the lowest Trainer role change protected fields on a sport (CVE-2026-107507). No CVSS scores were attached to the records at publication and no exploitation has been reported. Primary: CVE records from WPScan.

Product
WordPress plugins: Anton Extensions; Mobile Builder; WeddingCity Lite; Prenotazioni; Envira Gallery; Dokan (WooCommerce multivendor); Squadeno
Versions
Anton Extensions through 1.2.2; Mobile Builder through 1.4.2; WeddingCity Lite through 1.0.4; Prenotazioni through 1.7.5; Envira Gallery before 1.16.2; Dokan before 5.2.0; Squadeno before 1.12.0
CVSS
Not scored in the CVE records at publication (11 Oct 2026)
Exploited in Australia?
unknown
Patch to
Update Envira Gallery to 1.16.2 or later, Dokan to 5.2.0 or later and Squadeno to 1.12.0 or later. Anton Extensions, Mobile Builder, WeddingCity Lite and Prenotazioni have no fixed release listed: deactivate and remove them until a fix ships. On sites that ran Anton Extensions, look for unexpected PHP files in uploads and theme folders; on Mobile Builder sites, review the administrator list for self-registered accounts

Primary: CVE.org — CVE-2026-104028 Anton Extensions <= 1.2.2 unauthenticated arbitrary file upload to RCE (WPScan CNA, published 11 Oct 2026) · Vendor: WPScan — Anton Extensions <= 1.2.2 unauthenticated arbitrary file upload · CVE: CVE-2026-104028, CVE-2026-103695, CVE-2026-103694, CVE-2026-106029, CVE-2026-103305, CVE-2026-104680, CVE-2026-104684, CVE-2026-107694, CVE-2026-107507 · WPScan — Mobile Builder <= 1.4.2 unauthenticated SQL injection via vendor_id (CVE-2026-103695); wire: cve.report 11 Oct

vulnerabilities