CVE-2026-42696: WordPress SiteVault – Backup, Restore, Migration & Cloning plugin <= 1.5.18 - Remote Code Execution (RCE) vulnerability
Unauthenticated Remote Code Execution (RCE) in SiteVault – Backup, Restore, Migration & Cloning <= 1.5.19 versions.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
No authentication or prior privileges are required. The supplied vector indicates network-reachable exploitation with low attack complexity and no user interaction.
Which deployments are exposed?
WordPress sites using the SiteVault – Backup, Restore, Migration & Cloning plugin in affected versions are exposed. The description identifies versions through 1.5.19, while the title identifies versions through 1.5.18.
What is the likely impact of successful exploitation?
Successful exploitation can result in remote code execution, allowing an attacker to execute code on the affected WordPress environment. The supplied severity vector indicates high potential impact to confidentiality, integrity, and availability, including beyond the vulnerable component's security scope.