CVE-2026-96349: WordPress SiteSkite plugin <= 2.1.8 - Remote Code Execution (RCE) vulnerability
Published Sep 30, 2026
·Updated
Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.
Affected Software
1 affected component
WordPress SiteSkite<=2.1.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress SiteSkite pluginto a version that resolves this vulnerability.Fixed in 2.2.0
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated remote attacker can exploit it; no account or user interaction is required.
2
What is the potential impact?
Successful exploitation can result in remote code execution with high confidentiality, integrity, and availability impact.
3
Which deployments are affected?
WordPress sites using the SiteSkite plugin version 2.1.8 or earlier are affected.