๐Ÿ” CVE Alert

CVE-2026-19718

HIGH 8.1

BlogVault, MalCare and WP Remote 5.16 - 6.62 - Unauthenticated Site Takeover via Connection Key Recovery

CVSS Score
8.1
EPSS Score
0.2%
EPSS Percentile
6th

The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service, and generate that secret with a weak pseudo-random number generator, allowing attackers to recover it and gain administrative access to the site.

Vendor unknown
Product blogvault backup & staging
Published Aug 26, 2026
Last Updated Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for unknown blogvault backup & staging

Be the first to know when new high vulnerabilities affecting unknown blogvault backup & staging are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / BlogVault Backup & Staging
5.16 < 6.65
Unknown / MalCare WordPress Security Plugin
5.16 < 6.65
Unknown / The WP Remote WordPress Plugin
5.16 < 6.65

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/68892d43-912d-421f-9376-8dc6e2e906bc/

Credits

Jakub Herman WPScan