CVE-2026-42696: SiteVault WordPress RCE
TL;DR - CVE-2026-42696 is a critical, unauthenticated remote code execution flaw in the WordPress SiteVault plugin. - NVD lists versions through 1.5.19 as affected; Patchstack references through 1.5.18, and no fixed version is confirmed. - Audit immediately, restrict exposure, and disable or remove the plugin if a confirmed fix is unavailable.
What Happened, in Brief
CVE-2026-42696 affects SiteVault – Backup, Restore, Migration & Cloning, a WordPress plugin used for backup, restoration, migration, and site-cloning workflows. The NVD record describes the issue as unauthenticated remote code execution, meaning an attacker may not need a valid WordPress account to reach the vulnerable functionality. Available records do not identify the vulnerable PHP function, route, request parameter, or exploit payload.
| Field | Assessment |
|---|---|
| CVE ID | CVE-2026-42696 |
| CVSS base score | 10.0, Critical |
| CVSS vector | Not supplied in the available NVD response |
| Attack vector | Remote, based on the unauthenticated RCE description |
| Authentication required | None reported |
| Affected product | WordPress SiteVault – Backup, Restore, Migration & Cloning |
| Affected versions | NVD: <= 1.5.19; Patchstack metadata/title: <= 1.5.18 |
| Patch available | No confirmed fixed version |
| CISA KEV status | Not listed |
The version discrepancy matters operationally. NVD identifies versions 1.5.19 and earlier as affected, while the retrieved Patchstack advisory title refers to versions 1.5.18 and earlier. Until the vendor or researcher resolves that difference, defenders should use the broader range and treat 1.5.19 and earlier as potentially vulnerable.
Analyst’s Take: Treat the broader NVD range as the working scope because no source has resolved the discrepancy. The absence of a confirmed fixed version makes inventory and containment more actionable than an assumed upgrade. The lack of a disclosed route or payload also limits the value of exploit-specific detection.
What’s the Root Cause?
The precise root cause has not been disclosed in the available primary-source material. The records do not name the vulnerable file, PHP function, WordPress REST route, AJAX action, upload handler, or parameter. They also do not establish whether the flaw involves command injection, unsafe deserialization, an unrestricted file upload, path traversal, or another implementation error.
That limitation prevents a reliable exploit-specific detection rule or configuration workaround. Security teams should not infer a technical mechanism from the RCE classification alone. An RCE result can arise from several different coding flaws, and applying an assumed mitigation could leave the vulnerable path accessible.
For incident response and threat hunting, record the root cause as not yet disclosed in the retrieved advisory material. Preserve web server logs, WordPress application logs, PHP logs, and filesystem timelines before making changes that could remove evidence. If a later vendor advisory or patch commit identifies the vulnerable component, update detection and scoping procedures accordingly.
Who Needs to Act
Organizations running the WordPress SiteVault – Backup, Restore, Migration & Cloning plugin should act, including sites where the plugin is installed but not routinely used. Backup and migration plugins may retain privileged access, process archive files, write to the web root, or expose operational endpoints. A plugin that appears inactive from a user perspective may still remain installed and reachable depending on its code and registration behavior.
The currently reported version ranges are:
- NVD: SiteVault 1.5.19 and earlier
- Patchstack page metadata/title: SiteVault 1.5.18 and earlier
- Confirmed fixed version: None identified in the available sources
Inventory all WordPress instances, including development, staging, customer-hosted, and abandoned sites. Check both the installed plugin version and whether the plugin directory remains on disk. Because no fixed version is confirmed, do not treat an upgrade to 1.5.19 as remediation. Under the conservative interpretation, 1.5.19 remains potentially vulnerable.
A practical inventory command for a WP-CLI-managed site is:
wp plugin list --fields=name,status,version,update --format=table
For a fleet, collect this output centrally and search specifically for the SiteVault plugin slug or display name. Verify the result against the plugin directory and the official WordPress distribution page, since local version metadata can be stale or manipulated.
Why This CVSS Score?
The reported CVSS base score is 10.0, the maximum severity rating. The score is consistent with the description of a remotely reachable vulnerability that requires no authentication and can result in remote code execution. Code execution on a WordPress host can allow an attacker to modify site content, steal application secrets, create administrator accounts, install persistence, access database credentials, or pivot to other systems.
The available NVD response did not include a CVSS vector string. The individual CVSS components therefore cannot be independently verified from the supplied record. Do not invent values for attack complexity, privileges, user interaction, scope, confidentiality, integrity, or availability. The only reported facts are the 10.0 base score and the unauthenticated RCE description.
The score should guide prioritization, but it does not prove active exploitation. CISA does not list this CVE in the Known Exploited Vulnerabilities catalog, and no verified public proof of concept was identified in the available research. Those facts reduce certainty about current exploitation, not the potential impact of an exposed vulnerable site.
Has It Been Exploited?
Active exploitation has not been confirmed in the available sources. CVE-2026-42696 is not listed in CISA KEV, and the supplied research did not identify a verified public proof-of-concept repository or exploit code. There is also no confirmed ransomware campaign or exploitation report associated with this CVE in the provided material.
This status does not mean exploitation is impossible or that monitoring can wait. The vulnerability is described as unauthenticated RCE, and WordPress sites are commonly scanned by automated attackers. A new exploit or technical disclosure could significantly reduce the time between discovery and exploitation, particularly if the vulnerable plugin is widely deployed.
Treat exposed instances as high risk even without confirmed exploitation. Prioritize sites that are internet-facing, host sensitive data, use shared hosting, expose administrative functions broadly, or lack centralized logging. Review historical telemetry because the absence of a current alert does not establish that older requests were benign.
How Do I Know If I’m Hit?
Start by determining whether the plugin is installed and which version is present. Inspect WordPress administrative inventories, WP-CLI output, deployment manifests, and the plugin directory. A site should be considered potentially affected if SiteVault is present at version 1.5.19 or earlier, regardless of whether administrators believe its backup features are unused.
The vulnerability-specific endpoint and payload are not disclosed, so there is no authoritative network signature available. Look for suspicious requests to the WordPress site followed by PHP process activity, new files, changed plugin files, unexpected scheduled tasks, new WordPress users, or outbound connections from the web server. Review events around the first signs of compromise, not only the current day.
Technical Notes
Search access logs for requests that may indicate automated probing of WordPress plugin paths. The following is a triage pattern, not a CVE-specific signature:
grep -Eai \
'sitevault|wp-admin/admin-ajax\.php|wp-json|xmlrpc\.php|/wp-content/plugins/' \
/var/log/nginx/access.log /var/log/apache2/access.log
Correlate suspicious requests with process and filesystem activity. For example:
find /var/www -type f -mtime -14 \
\( -name '*.php' -o -name '*.phtml' -o -name '*.phar' \) \
-printf '%TY-%Tm-%Td %TH:%TM %p\n' | sort
Also check for unexpected WordPress users and administrator-level accounts:
wp user list --role=administrator --fields=ID,user_login,user_registered,roles
These checks cannot prove that CVE-2026-42696 was exploited because the vulnerable route and payload are unknown. They can identify common post-exploitation indicators and help determine whether a vulnerable installation requires incident response rather than simple remediation.
What Do I Do About It?
No fixed version has been confirmed in the available NVD or Patchstack material. Do not claim that upgrading to 1.5.19 resolves the issue. Because NVD lists 1.5.19 and earlier as affected, move to a newer release only after verifying through the official WordPress plugin distribution page, vendor release notes, or a later authoritative advisory that the release explicitly fixes CVE-2026-42696.
If no confirmed fixed release is available, disable or remove the plugin after preserving required backups and coordinating with the site owner. For a WP-CLI-managed installation:
wp plugin deactivate sitevault-backup-restore-migration
wp plugin uninstall sitevault-backup-restore-migration
The exact plugin slug may differ from the display name in a local installation. Run wp plugin list first and substitute the installed slug. Do not uninstall the plugin until required backup archives, migration data, and recovery procedures have been validated.
If removal is not immediately possible, reduce exposure with layered controls. Restrict access to the WordPress administration surface and any plugin-related routes at the reverse proxy or web application firewall, limit outbound network access from the web server, enforce least privilege for the web-server account, and increase logging. These are compensating controls, not a confirmed fix, because the affected endpoint and exploit conditions have not been disclosed.
For organizations managing access credentials across multiple WordPress sites, a password manager such as Try 1Password → can help enforce unique credentials and support credential rotation. Endpoint and malware monitoring tools such as Get Bitdefender → may also complement server-side logging, but neither replaces patch verification, plugin removal, or incident response.
After containment, inspect the host for unauthorized PHP files, modified core or plugin files, new WordPress users, altered scheduled tasks, suspicious database options, and stolen credentials. Rotate WordPress salts, database credentials, API keys, and hosting credentials if compromise is suspected. Restore from a known-good backup only after determining that the backup itself is trustworthy.
If the affected site processes payment-card data, document the remediation and investigation steps as part of the organization’s security and compliance records. The related PCI DSS guidance can help clarify broader responsibilities, although PCI DSS does not replace the technical response required for this vulnerability.
Also review how staff and administrators may be targeted after a compromise. Social-engineering awareness, including smishing defense best practices, can reduce the risk of stolen credentials being used to regain access.
Where This Comes From
The primary references available for this assessment are:
-
NVD: CVE-2026-42696
Records the CVE, critical 10.0 score, unauthenticated RCE description, and affected range of SiteVault versions through 1.5.19. -
Patchstack advisory for SiteVault
Identifies the SiteVault plugin and references a range through 1.5.18 in the page title or metadata. The retrieved material did not confirm a fixed version or mitigation. -
CISA Known Exploited Vulnerabilities Catalog
The available lookup did not list CVE-2026-42696. This means there is no CISA KEV confirmation of exploitation, not that exploitation has been ruled out.
The sources disagree on the upper affected version and do not identify a fixed release, so defenders should track the issue as unresolved. Recheck the vendor’s official plugin listing and release notes before re-enabling SiteVault. Update internal advisories when an authoritative version clarification or patch becomes available.
This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.