VYPR

WeddingCity Lite

by WordPress

CVEs (1)

  • CVE-2026-106029Oct 11, 2026
    risk 0.00cvss —epss —

    The WeddingCity Lite WordPress plugin through 1.0.4 does not perform any authorisation or validity checks before deleting posts, pages and media attachments, allowing unauthenticated attackers to permanently delete arbitrary content site-wide.