CVE-2026-81805
—Unauthenticated Privilege Escalation in WordPress SiteSkite Plugin (2.1.5 and earlier)
SiteSkite, a WordPress plugin, versions 2.1.5 and earlier contain a privilege escalation flaw caused by incorrect assignment of privileges (CWE-266), in which network-reachable functionality grants elevated access without requiring authentication. An unauthenticated attacker can trigger it remotely (AV:N) with no user interaction, although the high attack complexity component of the CVSS score means successful exploitation depends on conditions not fully under the attacker's control. A successful attack carries high impact on confidentiality and integrity (C:H/I:H), consistent with an attacker gaining elevated privileges, such as administrative access to the affected WordPress site. Any WordPress installation running SiteSkite 2.1.5 or earlier is affected, though the plugin's install base is not documented in the available data. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation exists at this time.
What to do: Update SiteSkite to the first release the vendor publishes after 2.1.5; until patched, deactivate the plugin to close the unauthenticated attack surface. Check the site for unexpected administrator accounts or modified user roles, and review web logs for unauthenticated requests to the plugin's endpoints.
| SiteSkite (WordPress plugin) | <= 2.1.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-266
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.