WordPress Plugin Vulnerabilities

Malcure Malware Shield < 19.9.7 - Multisite Subsite Admin+ Arbitrary File Write and Deletion via wpmr_ajax_request

Description

The plugin does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and delete arbitrary files in the network's shared filesystem, which can lead to remote code execution.

Proof of Concept

Affects Plugins

Fixed in 19.9.7

References

Classification

Type
NO AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
Charles Vosburgh
Submitter
Charles Vosburgh
Verified
Yes

Timeline

Publicly Published
2026-09-25 (about 2 days ago)
Added
2026-09-25 (about 1 day ago)
Last Updated
2026-09-25 (about 1 day ago)

Other