MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 10 h ago, last 10 h ago, peak #12

Critical unauthenticated RCE flaw found in SiteVault plugin

Original: ๐Ÿšจ EUVD-2026-96437 ๐Ÿ“Š Score: 10.0/10 (CVSS v3.1) ๐Ÿ“ฆ Product: SiteVault โ€“ Backup, Restore, Migration & Cloning ๐Ÿข Vendor:

A maximum-severity vulnerability, tracked as EUVD-2026-96437, has been disclosed in the SiteVault backup, restore, migration and cloning plugin by vendor Royal Plugins. The flaw carries a CVSS v3.1 score of 10.0 out of 10 and allows unauthenticated remote code execution, meaning attackers need no credentials to exploit it. Security advisories list the update as of 10 October 2026, and administrators running the plugin are being urged to patch immediately.

Why now: A perfect-score unauthenticated remote code execution vulnerability is exactly the kind of flaw attackers rush to exploit, so site admins are scrambling to patch.

SiteVaultRoyal PluginsEUVD-2026-96437

Open on mastodon โ†’

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1791811