CVE-2026-19718
Received Received - Intake

Authentication Bypass in BlogVault MalCare WP Remote

Vulnerability report for CVE-2026-19718, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: WPScan

Description

The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service, and generate that secret with a weak pseudo-random number generator, allowing attackers to recover it and gain administrative access to the site.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-26
AI Q&A
2026-08-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
blogvault backup_and_staging to 6.65 (exc)
malcare wordpress_security_plugin to 6.65 (exc)
wp_remote wordpress_plugin to 6.65 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects three WordPress plugins: BlogVault Backup & Staging, MalCare WordPress Security, and The WP Remote. They fail to prevent unauthenticated users from accessing data tied to a secret that links a site to its remote management service. Additionally, the secret is generated using a weak pseudo-random number generator, making it easier for attackers to recover and gain administrative access to the site.

Impact Analysis

Attackers could exploit this to gain full administrative control over your WordPress site without authentication. This could lead to unauthorized data access, modification, or deletion, and potentially compromise all site content and user accounts.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR and HIPAA requirements for data protection and access control. Organizations may face legal penalties, reputational damage, and loss of compliance certifications.

Mitigation Strategies

Update the affected plugins (BlogVault Backup & Staging, MalCare WordPress Security Plugin, WP Remote) to version 6.65 or later to address the weak secret generation and unauthorized data access issues.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19718. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart