CVE-2026-93513: WordPress SiteSkite plugin <= 2.1.7 - Insecure Direct Object References (IDOR) vulnerability
Published Sep 23, 2026
·Updated
Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions.
Affected Software
1 affected component
WordPress SiteSkite plugin<=2.1.7
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress SiteSkite Pluginto a version that resolves this vulnerability.Fixed in 2.1.8
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is exploitable by a user with Contributor-level access. It does not require user interaction.
2
What impact can successful exploitation have?
Successful exploitation can affect integrity, meaning an attacker may be able to make unauthorized changes. The available data does not indicate confidentiality or availability impact.
3
Which SiteSkite versions are affected?
SiteSkite versions 2.1.7 and earlier are affected.