ZeroHour

CVE-2026-81805

Unauthenticated Privilege Escalation in WordPress SiteSkite Plugin (2.1.5 and earlier)

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

SiteSkite, a WordPress plugin, versions 2.1.5 and earlier contain a privilege escalation flaw caused by incorrect assignment of privileges (CWE-266), in which network-reachable functionality grants elevated access without requiring authentication. An unauthenticated attacker can trigger it remotely (AV:N) with no user interaction, although the high attack complexity component of the CVSS score means successful exploitation depends on conditions not fully under the attacker's control. A successful attack carries high impact on confidentiality and integrity (C:H/I:H), consistent with an attacker gaining elevated privileges, such as administrative access to the affected WordPress site. Any WordPress installation running SiteSkite 2.1.5 or earlier is affected, though the plugin's install base is not documented in the available data. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation exists at this time.

What to do: Update SiteSkite to the first release the vendor publishes after 2.1.5; until patched, deactivate the plugin to close the unauthenticated attack surface. Check the site for unexpected administrator accounts or modified user roles, and review web logs for unauthenticated requests to the plugin's endpoints.

Affected
SiteSkite (WordPress plugin)<= 2.1.5
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.

Ecosystems
WordPress
Weakness
CWE-266
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.