OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-106029 (CVSS 7.5)

NVD · officialPublished Oct 11, 2026Risk 23/100EPSS 0.1%

The WeddingCity Lite WordPress plugin through 1.0.4 does not perform any authorisation or validity checks before deleting posts, pages and media attachments, allowing unauthenticated attackers to permanently delete arbitrary content site-wide.

CVSS
7.5
AV:NetworkAC:LowPR:NoneUI:NoneC:NoneI:HighA:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source