Description
Unauthenticated Remote Code Execution (RCE) in SiteVault – Backup, Restore, Migration &amp; Cloning <= 1.5.19 versions.
Published: 2026-10-10
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows unauthenticated injection of arbitrary PHP code via the WordPress SiteVault plugin’s input handling, leading to full remote code execution on the underlying server. The flaw is a classic code‑injection weakness (CWE‑94) that grants attackers the ability to execute any commands, exfiltrate data, or alter site functionality, thereby compromising confidentiality, integrity, and availability.

Affected Systems

All WordPress sites running Royal Plugins’ SiteVault – Backup, Restore, Migration & Cloning plugin version 1.5.18 or earlier (including 1.5.19 as noted in the description) are affected. The plugin can be present on any publicly accessible WordPress installation.

Risk and Exploitability

The CVSS score of 10 reflects the maximum severity of the flaw. Although no EPSS score is currently available, the lack of authentication requirement and the remote nature of the attack vector imply a high likelihood of exploitation in practice. The vulnerability is not yet listed in CISA’s KEV catalog, but the sheer impact and ease of exploitation make it a priority for immediate remediation.

Generated by OpenCVE AI on October 10, 2026 at 20:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update SiteVault to the latest version, ensuring the plugin is at least 1.5.19 or newer.
  • If an upgrade is not feasible, uninstall or deactivate the plugin to eliminate the attack surface.
  • If the plugin must remain for emergency reasons, restrict access to its REST API endpoints using a firewall or a security plugin that blocks unauthenticated requests.

Generated by OpenCVE AI on October 10, 2026 at 20:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Remote Code Execution (RCE) in SiteVault – Backup, Restore, Migration &amp; Cloning <= 1.5.19 versions.
Title WordPress SiteVault – Backup, Restore, Migration & Cloning plugin <= 1.5.18 - Remote Code Execution (RCE) vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T19:35:08.522Z

Reserved: 2026-04-29T09:05:01.790Z

Link: CVE-2026-42696

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T20:16:35.313

Modified: 2026-10-10T20:16:35.313

Link: CVE-2026-42696

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T20:30:06Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')