CVE-2026-106029: WeddingCity Lite <= 1.0.4 - Unauthenticated Arbitrary Post and Attachment Deletion
Published Oct 11, 2026
·Updated
The WeddingCity Lite WordPress plugin through 1.0.4 does not perform any authorisation or validity checks before deleting posts, pages and media attachments, allowing unauthenticated attackers to permanently delete arbitrary content site-wide.
Affected Software
1 affected component
WeddingCity WeddingCity Lite WordPress plugin<=1.0.4
Event History
Oct 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
DescriptionSeverityWeakness