SiteVault 1.5.19: Code Injection Flaw Enables Critical Unauthenticated Remote Code Execution
Royal Plugins SiteVault plugin allows unauthenticated remote code execution in versions up to 1.5.19, rated critical by NVD.

Key points
- CVE-2026-42696 affects SiteVault versions up to 1.5.19
- The NVD rates the vulnerability as critical with a CVSS score of 10
- The flaw enables unauthenticated remote code execution via CWE-94
The National Vulnerability Database published CVE-2026-42696, identifying a critical security flaw in the SiteVault – Backup, Restore, Migration & Cloning plugin. Developed by Royal Plugins, this WordPress extension manages site backups and cloning. The vulnerability allows attackers to execute arbitrary code on affected servers without needing user credentials. Security teams should treat this as an immediate priority due to the complete lack of authentication requirements for exploitation.
Root cause
The underlying weakness is classified as CWE-94, which relates to code injection flaws. According to the NVD record, the specific issue permits unauthenticated remote code execution. This means the application processes external input in a way that allows malicious code to run on the host system. The flaw exists within the core functionality of the backup and migration tools provided by the plugin, bypassing standard security checks.
Attack path
An attacker does not need valid login credentials to exploit this vulnerability. The NVD description explicitly states the RCE is unauthenticated. This allows any individual with network access to the WordPress site to send crafted requests to the plugin. Once the malicious payload is processed, the attacker gains full control over the server environment. This direct path significantly increases the risk of widespread compromise across multiple sites.
Affected versions
The vulnerability impacts all versions of the SiteVault plugin up to and including 1.5.19. Royal Plugins has released these versions to the WordPress repository. Any installation running version 1.5.19 or lower is vulnerable to CVE-2026-42696. Organizations must verify their current plugin version immediately. There are no partial mitigations mentioned for older versions; upgrading is the only confirmed path to remediation.
Mitigation
- Identify all WordPress installations using the SiteVault plugin
- Verify the current version of the installed plugin
- Upgrade to a version higher than 1.5.19 if available
- Scan server logs for signs of unauthorized code execution
What to do and how to stay safe: SiteVault
- Audit your WordPress plugins to locate SiteVault installations
- Check version numbers against the vulnerable list up to 1.5.19
- Monitor server access logs for suspicious unauthenticated requests
- Prepare to apply updates once a patched version is released
Step-by-step guide: Out-of-band patches: what small businesses need to know
General security guidance from the Firewall Pulse newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
What is the CVSS score for CVE-2026-42696?
The National Vulnerability Database assigns a CVSS score of 10, rating it as critical.
Which plugin versions are affected by this vulnerability?
SiteVault – Backup, Restore, Migration & Cloning versions up to 1.5.19 are affected.
Is authentication required to exploit this flaw?
No, the NVD records state that the remote code execution is unauthenticated.



