Sploitus Critical RCE Vulnerabilities Disclosed in Popular WordPress Plugins
Article Content
- •CVE-2026-96349 in SiteSkite allows unauthenticated RCE via API key exploitation.
- •CVE-2026-92966 in LatePoint enables arbitrary shortcode execution through user inputs.
- •Patches for both vulnerabilities were released on September 30 and October 1, 2026.
Multiple critical vulnerabilities have been disclosed affecting popular WordPress plugins, including SiteSkite and LatePoint. CVE-2026-96349 and CVE-2026-92966 both allow unauthenticated remote code execution, with CVSS scores of 10.0 and 9.1 respectively. The SiteSkite plugin flaw allows attackers to exploit a long-lived API key for admin access, while the LatePoint vulnerability enables arbitrary shortcode execution through user input. Both vulnerabilities are critical due to their potential for and have been assigned proof-of-concept (PoC) code. SiteSkite's patch was released on September 30, 2026, while LatePoint's fix was issued on October 1, 2026. Security professionals are urged to update their plugins immediately to mitigate these risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-102424 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of SiteSkite and LatePoint are affected?
Are these vulnerabilities being actively exploited?
What should I do to protect my site?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…