CVE-2026-96896 PUBLISHED

Malcure Malware Shield < 19.9.7 - Multisite Subsite Admin+ Arbitrary File Write and Deletion via wpmr_ajax_request

Assigner: WPScan
Reserved: 23.09.2026 Published: 27.09.2026 Updated: 27.09.2026

The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and delete arbitrary files in the network's shared filesystem, which can lead to remote code execution.

Product Status

Vendor Unknown
Product Malcure Malware Shield — Removal, Repair, Monitor
Versions Default: unaffected
  • affected from 0 to 19.9.7 (excl.)

Credits

  • Charles Vosburgh finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE