Sceawere

Vulnerability Detail

CVE-2026-42696UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated RCE in SiteVault

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
5h ago
Vendor
Royal Plugins
Product
SiteVault – Backup, Restore, Migration & Cloning
Attack Type
CWE-94 Improper Control of Generation of Code ('Code Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Remote Code Execution (RCE) in SiteVault – Backup, Restore, Migration &amp; Cloning <= 1.5.19 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-10-10T20:16:35.313Z",
  "pubdate": "2026-10-10T20:16:35.313Z",
  "executiveSummary": "The SiteVault – Backup, Restore, Migration & Cloning plugin for WordPress is vulnerable to an unauthenticated Remote Code Execution (RCE) flaw in versions 1.5.19 and below.\nThe vulnerability originates from a critical security oversight in input validation or component handling within the plugin's core functionality, allowing remote, unauthenticated attackers to execute arbitrary system commands on the underlying web server.\nThis constitutes a severe security risk as it permits complete system compromise, unauthorized data exfiltration, and potential lateral movement within the hosting environment.\nThe vulnerability is reachable via the public network and requires no prior authentication or administrative privileges to exploit.\nDue to the nature of RCE, the impact is catastrophic, potentially leading to a full server takeover or total loss of confidentiality, integrity, and availability of the affected WordPress instance.",
  "technicalDetails": "The vulnerability exists within the SiteVault – Backup, Restore, Migration & Cloning plugin (<= 1.5.19) due to improper sanitization or inadequate verification of user-supplied input provided to specific plugin endpoints or administrative functions.\nThe core issue likely resides in the handling of backup or migration parameters, where input data is passed to system-level functions (such as PHP's exec(), system(), or shell_exec()) without sufficient validation or escaping mechanisms.\nAn unauthenticated attacker can leverage this flaw by sending a crafted HTTP request to the target site. Since the vulnerable code paths do not enforce authorization checks or nonce verification, the request is processed by the server with the privileges of the web user (typically www-data).\nThe attack flow typically involves the identification of a reachable script or action handler within the plugin that interfaces with the server's shell or filesystem. By injecting malicious command-line arguments or payloads into the affected parameter, an attacker can hijack the execution context.\nOnce the payload is processed, the attacker gains the ability to execute arbitrary commands, facilitating the deployment of web shells, the execution of reverse shells, or the modification of site configurations. Post-exploitation activities are limited only by the permissions of the web server process itself.\nThis vulnerability is classified as critical because it bypasses all application-layer authentication protocols. The lack of input normalization or parameterized execution allows for command injection, which is a direct execution path from the external network to the server's operating system environment."
}
CVE-2026-42696: Unauthenticated RCE in SiteVault (CRITICAL Severity, CVSS: 10.0) | Sceawere