CVE-2026-96896
Received Received - Intake

Malcure Malware Shield WordPress Plugin Auth Bypass RCE

Vulnerability report for CVE-2026-96896, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: WPScan

Description

The Malcure Malware Shield β€” Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and delete arbitrary files in the network's shared filesystem, which can lead to remote code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-27
AI Q&A
2026-09-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
malcure malware_shield to 19.9.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Malcure Malware Shield WordPress plugin versions before 19.9.7. It allows users with a subsite administrator role in a multisite network to exploit a missing authorization check in an AJAX action. This enables them to write and delete arbitrary files in the network's shared filesystem, which could lead to remote code execution.

Detection Guidance

Check the installed version of the Malcure Malware Shield plugin in your WordPress admin panel. If it is below 19.9.7, the vulnerability is present. Review server logs for unauthorized file write or delete operations, particularly from users with subsite administrator roles.

Impact Analysis

An attacker with a subsite administrator role could exploit this to gain full control over the WordPress multisite network by executing arbitrary code. This could result in data breaches, malware distribution, or complete site compromise.

Compliance Impact

This vulnerability could lead to unauthorized access and data exfiltration, violating GDPR's data protection requirements and HIPAA's security rules. Organizations may face fines, legal penalties, and reputational damage due to non-compliance.

Mitigation Strategies

Update the Malcure Malware Shield plugin to version 19.9.7 or later immediately. Remove unnecessary subsite administrator accounts and restrict file write permissions on the server to limit potential exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96896. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart