WordPress (Patchstack, CVEs 10 Oct): Everest Backup (3,000+ sites) and SiteVault let anyone run code on the server with no fix released; miniOrange OTP Verification and rtMedia fix unauthenticated takeover and file-deletion bugs (9.8)
Patchstack, acting as CVE numbering authority, published CVE records on 10 October 2026 for a set of WordPress plugin flaws it had disclosed in its database between 6 and 9 October. Two backup plugins have unauthenticated remote code execution and no official patch: CVE-2026-39802 in Everest Backup up to 2.3.13 (3,000+ active installs on WordPress.org; CVSS 3.1 8.1; Patchstack has a mitigation rule for its customers) and CVE-2026-42696 in SiteVault – Backup, Restore, Migration & Cloning up to 1.5.19 (CVSS 10; a small install base; 1.5.19, the latest release, is still listed as vulnerable). Two plugins have fixes: CVE-2026-106610 in miniOrange OTP Verification up to 5.5.7 (5,000+ installs) lets an unauthenticated attacker escalate privileges (9.8), fixed in 5.5.8; and CVE-2026-105892 in rtMedia for WordPress, BuddyPress and bbPress up to 4.7.13 (7,000+ installs) is an unauthenticated path traversal that lets attackers delete files and break the site (9.8), fixed in 4.7.14 (another CNA also published it as CVE-2026-89301). Further unfixed issues: unauthenticated privilege escalation in Tonda Membership up to 1.0.1 (CVE-2026-62022, 9.8; Patchstack's rule blocks its Facebook/Google sign-in), unauthenticated arbitrary file upload in Tailored Tools up to 3.0.3 (CVE-2026-62025, 9.0), subscriber-level file upload in CodeBard Help Desk up to 1.1.2 (CVE-2026-62024, 9.9), subscriber-level PHP object injection in Dynamic User Directory up to 2.4 (CVE-2026-42719, 9.8), and subscriber-to-admin escalation in AIWU up to 1.5.9 (CVE-2026-39801, 9.8), which WordPress.org has closed for a security issue. AFFI – Affiliate Marketing for WooCommerce up to 1.0.10 has unauthenticated PHP object injection (CVE-2026-104398, 9.8), fixed in 1.0.11. No exploitation has been reported. Primary: Patchstack advisories; CVE records.
- Product
- WordPress plugins: Everest Backup; SiteVault – Backup, Restore, Migration & Cloning; miniOrange OTP Verification; rtMedia for WordPress, BuddyPress and bbPress; Tonda Membership; Tailored Tools; CodeBard Help Desk; Dynamic User Directory; AIWU; AFFI – Affiliate Marketing for WooCommerce
- Versions
- Everest Backup <= 2.3.13; SiteVault <= 1.5.19; miniOrange OTP Verification <= 5.5.7; rtMedia <= 4.7.13; Tonda Membership <= 1.0.1; Tailored Tools <= 3.0.3; CodeBard Help Desk <= 1.1.2; Dynamic User Directory <= 2.4; AIWU <= 1.5.9; AFFI <= 1.0.10
- CVSS
- SiteVault 10; miniOrange OTP Verification, rtMedia, Tonda Membership, Dynamic User Directory, AIWU, AFFI 9.8; CodeBard Help Desk 9.9; Tailored Tools 9.0; Everest Backup 8.1 (CVSS 3.1, Patchstack)
- Exploited in Australia?
- unknown
- Patch to
- Update miniOrange OTP Verification to 5.5.8, rtMedia to 4.7.14 and AFFI to 1.0.11 or later. Everest Backup, SiteVault, Tonda Membership, Tailored Tools, CodeBard Help Desk, Dynamic User Directory and AIWU have no fixed release listed: deactivate and remove them (use another backup plugin) until a fix ships, or put a web application firewall rule in front of the site. Check sites that ran them for unknown administrator accounts and unexpected PHP files in uploads and plugin folders
Primary: Patchstack — Everest Backup <= 2.3.13 unauthenticated Remote Code Execution (CVE-2026-39802, published 6 Oct 2026; no official patch) · Vendor: Patchstack — miniOrange OTP Verification <= 5.5.7 Privilege Escalation (CVE-2026-106610, fixed in 5.5.8) · CVE: CVE-2026-39802, CVE-2026-42696, CVE-2026-106610, CVE-2026-105892, CVE-2026-89301, CVE-2026-62022, CVE-2026-62025, CVE-2026-62024, CVE-2026-42719, CVE-2026-39801, CVE-2026-104398 · Patchstack — SiteVault <= 1.5.19 unauthenticated Remote Code Execution (CVE-2026-42696, CVSS 10, no official patch); wire: cve.report 11 Oct
