CVE-2026-96896
Malcure Malware Shield < 19.9.7 - Multisite Subsite Admin+ Arbitrary File Write and Deletion via wpmr_ajax_request
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and delete arbitrary files in the network's shared filesystem, which can lead to remote code execution.
| Vendor | unknown |
| Product | malcure malware shield — removal, repair, monitor |
| Published | Sep 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown malcure malware shield — removal, repair, monitor
Be the first to know when new unknown vulnerabilities affecting unknown malcure malware shield — removal, repair, monitor are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / Malcure Malware Shield — Removal, Repair, Monitor
0 < 19.9.7
References
Credits
Charles Vosburgh WPScan