Junglewise Threat Intelligence

CVE-2026-81805: SiteSkite unauthenticated privilege escalation

CVE-2026-81805 · Severity: high · CVSS 8.1 · Published 2026-09-10

Executive brief

SiteSkite is a WordPress plugin used to extend site functionality. An unauthenticated attacker can exploit this privilege escalation vulnerability to gain full administrative control over an affected WordPress site, allowing them to modify content, steal data, install malware, or take the site offline.

Technical details

This is an unauthenticated privilege escalation vulnerability in the SiteSkite WordPress plugin affecting versions 2.1.5 and earlier. A low-privilege or unauthenticated user can escalate their privileges to administrator level, gaining complete control of the WordPress installation. The vulnerability is classified under OWASP A7 (Identification and Authentication Failures). The attack requires no authentication and can be exploited remotely. A patch is available in version 2.1.6 and later.

Affected products

  • SiteSkite SiteSkite <=2.1.5

Timeline

  • 2026-09-09: disclosed
  • 2026-09-10: patched: Version 2.1.6 released

References

Related threats