Mmastodon TechnologyCybersecurity first seen 8 h ago, last 8 h ago, peak #12
Critical unauthenticated RCE flaw found in SiteVault plugin
Original: ๐จ EUVD-2026-96437 ๐ Score: 10.0/10 (CVSS v3.1) ๐ฆ Product: SiteVault โ Backup, Restore, Migration & Cloning ๐ข Vendor:
A maximum-severity vulnerability, tracked as EUVD-2026-96437, has been disclosed in the SiteVault backup, restore, migration and cloning plugin by vendor Royal Plugins. The flaw carries a CVSS v3.1 score of 10.0 out of 10 and allows unauthenticated remote code execution, meaning attackers need no credentials to exploit it. Security advisories list the update as of 10 October 2026, and administrators running the plugin are being urged to patch immediately.
Why now: A perfect-score unauthenticated remote code execution vulnerability is exactly the kind of flaw attackers rush to exploit, so site admins are scrambling to patch.
SiteVaultRoyal PluginsEUVD-2026-96437
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/1791811