Skip to content
Critical RCE Vulnerabilities Disclosed in Popular WordPress Plugins

Critical RCE Vulnerabilities Disclosed in Popular WordPress Plugins

First seen 1 Oct 2026, 09:00 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 10:03 UTC
  • •CVE-2026-96349 in SiteSkite allows unauthenticated RCE via API key exploitation.
  • •CVE-2026-92966 in LatePoint enables arbitrary shortcode execution through user inputs.
  • •Patches for both vulnerabilities were released on September 30 and October 1, 2026.

Multiple critical vulnerabilities have been disclosed affecting popular WordPress plugins, including SiteSkite and LatePoint. CVE-2026-96349 and CVE-2026-92966 both allow unauthenticated remote code execution, with CVSS scores of 10.0 and 9.1 respectively. The SiteSkite plugin flaw allows attackers to exploit a long-lived API key for admin access, while the LatePoint vulnerability enables arbitrary shortcode execution through user input. Both vulnerabilities are critical due to their potential for and have been assigned proof-of-concept (PoC) code. SiteSkite's patch was released on September 30, 2026, while LatePoint's fix was issued on October 1, 2026. Security professionals are urged to update their plugins immediately to mitigate these risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-19
CVE-2026-67364 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-29
CVE-2026-102425 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-29
CVE-2026-102424 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-30
CVE-2026-96349 published
SiteSkite plugin vulnerability disclosed, allowing unauthenticated RCE via API key.
Sploitus
2026-10-01
CVE-2026-92966 published
LatePoint plugin vulnerability disclosed, enabling arbitrary shortcode execution.
Sploitus
2026-10-01
Patches released for vulnerabilities
SiteSkite and LatePoint released patches to address critical vulnerabilities.
Sploitus

More articles in this cluster (3)

Following this threat?

Track CVE-2026-102424 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of SiteSkite and LatePoint are affected?
Versions 2.1.8 and earlier of SiteSkite and versions prior to 5.7.1 of LatePoint are affected.
Are these vulnerabilities being actively exploited?
While PoC code exists, there is no confirmed active exploitation reported in the wild.
What should I do to protect my site?
Immediately update to the latest versions of SiteSkite and LatePoint to mitigate these vulnerabilities.