CVE-2026-93513
Deferred Deferred - Pending Action

Contributor IDOR in SiteSkite <= 2.1.7

Vulnerability report for CVE-2026-93513, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: Patchstack

Description

Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-24
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
siteskite siteskite to 2.1.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object References (IDOR) issue in the WordPress SiteSkite Plugin versions 2.1.7 and below. It allows contributors or developers to manipulate IDs in URLs to access or expose other users' data without proper authorization.

Detection Guidance

To detect this IDOR vulnerability in SiteSkite <= 2.1.7, manually review plugin files for direct object references in URLs or API endpoints. Check for exposed user data access via manipulated IDs. Enable debug logs in WordPress to monitor suspicious access patterns. Use security plugins like Wordfence or Patchstack to scan for known vulnerabilities.

Impact Analysis

If you have a WordPress site using SiteSkite <= 2.1.7, an attacker with contributor or developer access could exploit this to view or modify other users' data. The impact is limited to users with these roles, and the severity is rated as low.

Compliance Impact

IDOR can lead to unauthorized data exposure, which may violate GDPR (data protection) or HIPAA (health data privacy) if user data is compromised. Compliance risks depend on the data accessed and applicable regulations.

Mitigation Strategies

Immediately update SiteSkite to version 2.1.8 or later. If updating is not possible, enable auto-updates for the plugin via Patchstack or your hosting provider. Restrict contributor/developer roles to minimize attack surface. Review and audit user permissions to ensure least privilege access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93513. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart