Impact
The vulnerability allows unauthenticated injection of arbitrary PHP code via the WordPress SiteVault plugin’s input handling, leading to full remote code execution on the underlying server. The flaw is a classic code‑injection weakness (CWE‑94) that grants attackers the ability to execute any commands, exfiltrate data, or alter site functionality, thereby compromising confidentiality, integrity, and availability.
Affected Systems
All WordPress sites running Royal Plugins’ SiteVault – Backup, Restore, Migration & Cloning plugin version 1.5.18 or earlier (including 1.5.19 as noted in the description) are affected. The plugin can be present on any publicly accessible WordPress installation.
Risk and Exploitability
The CVSS score of 10 reflects the maximum severity of the flaw. Although no EPSS score is currently available, the lack of authentication requirement and the remote nature of the attack vector imply a high likelihood of exploitation in practice. The vulnerability is not yet listed in CISA’s KEV catalog, but the sheer impact and ease of exploitation make it a priority for immediate remediation.
OpenCVE Enrichment