Description
Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions.
Published: 2026-09-23
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized data access
Action: Patch Update
AI Analysis

Impact

The CVE describes an Insecure Direct Object Reference vulnerability in the WordPress SiteSkite plugin. The flaw allows an attacker with sufficient access to bypass authentication checks and retrieve or modify resources that should be restricted to authorized users, leading to potential disclosure or alteration of sensitive content.

Affected Systems

All installations of the SiteSkite plugin up to and including version 2.1.7 on WordPress sites are impacted. Users running the affected plugin version are potentially exposed.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is web‑based, involving manipulation of URL parameters or API calls that reference protected objects. Exploitation probably requires authenticated access and input manipulation, enabling the attacker to access data unintended for them.

Generated by OpenCVE AI on September 23, 2026 at 20:31 UTC.

Remediation

Vendor Solution

Update the WordPress SiteSkite Plugin to the latest available version (at least 2.1.8).


OpenCVE Recommended Actions

  • Upgrade the SiteSkite plugin to version 2.1.8 or later, where the IDOR flaw has been fixed.
  • Restrict the capabilities of user roles that have access to the compromised functionality, ensuring only necessary permissions are granted.
  • Enable comprehensive logging for access attempts to SiteSkite resources and review logs regularly for signs of unauthorized activity.

Generated by OpenCVE AI on September 23, 2026 at 20:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Siteskite
Siteskite siteskite
Wordpress
Wordpress wordpress
Vendors & Products Siteskite
Siteskite siteskite
Wordpress
Wordpress wordpress

Wed, 23 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions.
Title WordPress SiteSkite plugin <= 2.1.7 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Siteskite Siteskite
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-23T19:43:49.626Z

Reserved: 2026-09-18T08:46:53.467Z

Link: CVE-2026-93513

cve-icon Vulnrichment

Updated: 2026-09-23T19:05:06.860Z

cve-icon NVD

Status : Deferred

Published: 2026-09-23T19:19:45.297

Modified: 2026-09-23T20:17:22.620

Link: CVE-2026-93513

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T20:45:09Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key