CVE-2026-105071: WordPress SiteVault – Backup, Restore, Migration & Cloning plugin <= 1.5.17 - Sensitive Data Exposure vulnerability
Published Oct 6, 2026
·Updated
Unauthenticated Sensitive Data Exposure in SiteVault – Backup, Restore, Migration & Cloning <= 1.5.17 versions.
Affected Software
1 affected component
SiteVault SiteVault – Backup, Restore, Migration & Cloning<=1.5.17
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress SiteVault – Backup, Restore, Migration & Cloning pluginto a version that resolves this vulnerability.Fixed in 1.5.18
Event History
Oct 6, 2026
CVE Published
via MITRE·08:35 AM
Data Sourced
via MITRE·08:35 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to attempt exploitation.
2
What is the potential impact?
The vulnerability can expose sensitive data. The supplied severity vector indicates high confidentiality impact, with no stated integrity or availability impact.
3
Which installations are affected?
SiteVault – Backup, Restore, Migration & Cloning versions 1.5.17 and earlier are identified as affected.