CVE-2026-106029
Received Received - Intake

Unauthenticated Post Deletion in WeddingCity Lite WordPress Plugin

Vulnerability report for CVE-2026-106029, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: WPScan

Description

The WeddingCity Lite WordPress plugin through 1.0.4 does not perform any authorisation or validity checks before deleting posts, pages and media attachments, allowing unauthenticated attackers to permanently delete arbitrary content site-wide.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown WeddingCity Lite 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The WeddingCity Lite WordPress plugin through version 1.0.4 has a vulnerability where it fails to perform authorization or validity checks before deleting posts, pages, and media attachments. This allows unauthenticated attackers to permanently delete any content on the site without needing access or permissions.

Detection Guidance

To detect this vulnerability, check if the WeddingCity Lite plugin version 1.0.4 or earlier is installed on your WordPress site. Inspect server logs for unusual deletion activities or unauthorized POST requests targeting post, page, or media endpoints.

Impact Analysis

This vulnerability can lead to permanent loss of critical website content such as posts, pages, and media files. Attackers could delete important data, disrupting website functionality and causing data loss for all users.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized deletion of personal or sensitive data. GDPR requires data integrity and access controls, while HIPAA mandates protection of health information. Unauthorized deletion violates these requirements.

Mitigation Strategies

Immediately disable or uninstall the WeddingCity Lite plugin if installed. Monitor your site for unauthorized deletions and restrict access to administrative functions until an official patch is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106029. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart