Sceawere
Vulnerability Detail
CVE-2026-105071UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SiteVault Unauthenticated Sensitive Data Exposure
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 16h ago
- Vendor
- Royal Plugins
- Product
- SiteVault – Backup, Restore, Migration & Cloning
- Attack Type
- CWE-201 Insertion of Sensitive Information Into Sent Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Sensitive Data Exposure in SiteVault – Backup, Restore, Migration & Cloning <= 1.5.17 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-06T09:17:40.893Z",
"pubdate": "2026-10-06T09:17:40.893Z",
"executiveSummary": "The SiteVault – Backup, Restore, Migration & Cloning plugin (versions 1.5.17 and below) contains a critical security vulnerability involving unauthenticated sensitive data exposure.\nThis flaw allows remote, unauthenticated attackers to access and exfiltrate sensitive configuration data, potentially including credentials, migration tokens, or system backup structures, without requiring any administrative privileges.\nThe vulnerability stems from improper access control mechanisms within the plugin's API or processing logic, which fails to validate the authentication state of the requester before serving sensitive information.\nBy exploiting this weakness, an attacker can gain deep insights into the site's environment, facilitating further lateral movement, full site compromise, or unauthorized backup retrieval.\nThe risk is categorized as high due to the lack of exploitation complexity; the vulnerability is accessible over the network, does not require user interaction, and provides a direct path for the unauthorized disclosure of proprietary or security-sensitive site configuration data.",
"technicalDetails": "The vulnerability exists within the SiteVault – Backup, Restore, Migration & Cloning plugin in versions 1.5.17 and prior. The root cause is the implementation of an improperly secured endpoint or function that fails to verify the session or capability of the request initiator, effectively granting public access to internal system metadata and configuration parameters.\nSpecifically, the plugin exposes sensitive site information through an unauthenticated route, likely intended for internal synchronization or migration tasks, but lacking the necessary REST API permission checks or nonce verification. An attacker can craft a direct HTTP request to the vulnerable endpoint to trigger the plugin's internal response mechanism.\nThe attack flow proceeds as follows: First, the attacker identifies the active instance of the SiteVault plugin on the target WordPress installation. Second, the attacker interacts with the exposed endpoint (typically via a GET or POST request targeting specific plugin-defined hooks or REST routes) without providing a valid authentication cookie or session token. Third, the plugin processes the request and returns a structured response—frequently in JSON format—containing sensitive environment details, path information, database connection strings, or site-specific tokens used for migration and cloning operations.\nBecause the application logic does not perform a 'current_user_can()' check or equivalent authorization validation prior to data retrieval, the server treats the unauthorized request as legitimate. The impact is significant, as this metadata can be utilized to craft further exploits, such as accessing remote storage containers, intercepting site migration processes, or mapping the internal file structure of the hosting server.\nThe vulnerability is exploitable remotely over standard HTTP/HTTPS protocols without prior knowledge of the site's administrative credentials. No specific configuration hardening is provided by the plugin to mitigate this, making all installations below version 1.5.17 susceptible to automated scanning and opportunistic exploitation by threat actors seeking to harvest sensitive site configuration data for large-scale attacks or targeted environment compromises."
}