POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
WordPresscritical

CVE-2026-96349 — WordPress SiteSkite ≤2.1.8 API-Key Autologin + MCP eval() RCE Chain

October 1, 2026 · 76 views

SiteSkite WordPress plugin ≤2.1.8: long-lived API key acts as unauthenticated admin bearer via ?token= autologin; REST/admin-ajax MCP abilities run siteskite_execute_php (eval) and file write. CVSS 10.0 Critical (CWE-94). Fixed in 2.2.0. Python PoC: check (readme ≤2.1.8), exploit with API key, mass hits/exploited, --lab. Marker POCBIT-96349-OK.

#wordpress#siteskite#plugin#rce#code-injection#cwe-94#autologin#mcp#critical#unauthenticated

CVE:

CVE-2026-96349

Date:

2026-10-01

Severity:

CRITICAL

Exploit source

Full PoC repository on GitHub (public).

Description

Overview

CVE-2026-96349 — SiteSkite WordPress plugin — unauthenticated remote code execution when the plugin’s API key is known (Patchstack / CVE Program; CVSS 10.0 Critical, CWE-94).

| | | |---|---| | Product | SiteSkite | | Affected | ≤ 2.1.8 | | Fixed | ≥ 2.2.0 (September 2026) | | Verify marker | POCBIT-96349-OK |

In ≤ 2.1.8, the stored siteskite_api_key doubles as an unauthenticated admin login bearer (?token= on /siteskite-autologin or front-end URLs). With the key, attackers call POST /wp-json/siteskite/v1/abilities/execute (or admin-ajax.php?action=siteskite_api) with X-SiteSkite-Key and run siteskite_execute_php (eval) or siteskite_write_file. 2.2.0 removes raw-key autologin (portal HMAC links only).

PoC page: https://pocbit.org/pocs/cve-2026-96349

GitHub: murrez/CVE-2026-96349

CVE.org: CVE-2026-96349

Patchstack: SiteSkite 2.1.8 RCE advisory

Attack chain (summary)

  1. Obtain victim SiteSkite API key (portal links, leaks, backups, url\tkey lists — exploit mode requires a key unless per-URL key is supplied).
  2. Optional: prove session via /?token=KEY or /siteskite-autologin?token=KEY.
  3. siteskite_execute_php → marker, or write_file / up.php drop under uploads.

Bundled tool (Python 3.10+)

Download cve-2026-96349.py — bundle extractor (poc.py, _engine.py, up.php).

pip install requests colorama

python cve-2026-96349.py
python poc.py --lab

python poc.py --check fofa_targets.txt
python poc.py fofa_targets.txt --key YOUR_SITESKITE_API_KEY
python poc.py urls.txt -t 24

python poc.py -u https://target.example --check
python poc.py -u https://target.example --key SITE_SKITE_KEY

Per-target keys in list files: https://site.example<TAB>api_key or pipe-separated. Env: SITESKITE_API_KEY / SITESKITE_KEY.

| Mode | Output | |------|--------| | check | hits.txt — readme ≤2.1.8, autologin fingerprint | | exploit | exploited.txt — RCE verified with marker |

Discovery hints

body="/wp-content/plugins/siteskite/"

Check mode does not brute-force API keys.

Remediation

  1. Upgrade SiteSkite to ≥ 2.2.0 immediately.
  2. Rotate API key after upgrade (old key was a login bearer).
  3. Disable unused MCP / advanced tools; audit ?token= and X-SiteSkite-Key in logs.

See also WordPress plugin vulnerabilities guide.

Legal and ethical use

Authorized security testing only.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →