Sceawere
Vulnerability Detail
CVE-2026-42696UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated RCE in SiteVault
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 10
- Creation Date
- 5h ago
- Vendor
- Royal Plugins
- Product
- SiteVault – Backup, Restore, Migration & Cloning
- Attack Type
- CWE-94 Improper Control of Generation of Code ('Code Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Remote Code Execution (RCE) in SiteVault – Backup, Restore, Migration & Cloning <= 1.5.19 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "10.0",
"pubDate": "2026-10-10T20:16:35.313Z",
"pubdate": "2026-10-10T20:16:35.313Z",
"executiveSummary": "The SiteVault – Backup, Restore, Migration & Cloning plugin for WordPress is vulnerable to an unauthenticated Remote Code Execution (RCE) flaw in versions 1.5.19 and below.\nThe vulnerability originates from a critical security oversight in input validation or component handling within the plugin's core functionality, allowing remote, unauthenticated attackers to execute arbitrary system commands on the underlying web server.\nThis constitutes a severe security risk as it permits complete system compromise, unauthorized data exfiltration, and potential lateral movement within the hosting environment.\nThe vulnerability is reachable via the public network and requires no prior authentication or administrative privileges to exploit.\nDue to the nature of RCE, the impact is catastrophic, potentially leading to a full server takeover or total loss of confidentiality, integrity, and availability of the affected WordPress instance.",
"technicalDetails": "The vulnerability exists within the SiteVault – Backup, Restore, Migration & Cloning plugin (<= 1.5.19) due to improper sanitization or inadequate verification of user-supplied input provided to specific plugin endpoints or administrative functions.\nThe core issue likely resides in the handling of backup or migration parameters, where input data is passed to system-level functions (such as PHP's exec(), system(), or shell_exec()) without sufficient validation or escaping mechanisms.\nAn unauthenticated attacker can leverage this flaw by sending a crafted HTTP request to the target site. Since the vulnerable code paths do not enforce authorization checks or nonce verification, the request is processed by the server with the privileges of the web user (typically www-data).\nThe attack flow typically involves the identification of a reachable script or action handler within the plugin that interfaces with the server's shell or filesystem. By injecting malicious command-line arguments or payloads into the affected parameter, an attacker can hijack the execution context.\nOnce the payload is processed, the attacker gains the ability to execute arbitrary commands, facilitating the deployment of web shells, the execution of reverse shells, or the modification of site configurations. Post-exploitation activities are limited only by the permissions of the web server process itself.\nThis vulnerability is classified as critical because it bypasses all application-layer authentication protocols. The lack of input normalization or parameterized execution allows for command injection, which is a direct execution path from the external network to the server's operating system environment."
}