{"error":0,"message":null,"data":{"name":"MalCare WordPress Security Plugin &#8211; Malware Scanner, Cleaner, Security Firewall","plugin":"malcare-security","link":"https:\/\/wordpress.org\/plugins\/malcare-security\/","latest":"1789645200","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"93cec96a030dc560117b195a6efac15607a074e41dfeebdc289046ae2b8f329f","name":"MalCare WordPress Security Plugin &#8211; Malware Scanner, Cleaner, Security Firewall [malcare-security] < 4.58","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.58","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"fd2a15caa8a8f2727f6a5c0569ecbd735696d652","name":"WordPress MalCare Security plugin <= 4.57 - Authenticated Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/malcare-security\/vulnerability\/wordpress-malcare-security-plugin-4-57-authenticated-cross-site-scripting-xss-vulnerability","description":"Authenticated Cross-Site Scripting (XSS) vulnerability discovered by Lenon Leite in WordPress MalCare Security plugin (versions <= 4.57).","date":"2021-05-05"}],"impact":[]},{"uuid":"c520fd4346fd038dc9bab62db21485fc432ad286f402b17246d8643ff609f628","name":"MalCare WordPress Security Plugin &#8211; Malware Scanner, Cleaner, Security Firewall [malcare-security] < 6.65","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.65","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-19718","name":"CVE-2026-19718","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-19718","description":"[en] The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin  WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service, and generate that secret with a weak pseudo-random number generator, allowing attackers to recover it and gain administrative access to the site.","date":"2026-08-26"},{"id":"1bb7812407927194021b5176de25ac68bff6e95a","name":"WordPress MalCare Security Plugin 5.16-6.62 is vulnerable to a high priority Broken Authentication","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/malcare-security\/vulnerability\/wordpress-malcare-wordpress-security-plugin-5-16-6-62-unauthenticated-site-takeover-via-connection-key-recovery-vulnerability","description":"<p>WordPress MalCare Security Plugin 5.16-6.62 is vulnerable to a high priority Broken Authentication<\/p><p>Software: MalCare Security<\/p><p>Fixed in version 6.65 <\/p><p>Affected Version 5.16-6.62<\/p><p>CVE: CVE-2026-19718<\/p>","date":"2026-08-26"},{"id":"f9a889cfb8110339cffea6f24942b163d69a28c1","name":"The WP Remote WordPress Plugin, Malcare Security, and BlogVault Backup & Staging < 6.65 - Unauthenticated Site Takeover via Brute Force","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/the-wp-remote-wordpress-plugin-malcare-security-and-blogvault-backup-staging-665-unauthenticated-site-takeover-via-brute-force","description":"Multiple plugins for WordPress are vulnerable to unauthenticated site takeover in various versions. This is due to a weak pseudo-random number generator that makes it possible for attackers to brute force and connect to the remote connection feature. This makes it possible for unauthenticated attackers to connect a site to their remote management software and take it over.","date":null}],"impact":{"cwe":[{"cwe":"CWE-287","name":"Improper Authentication","description":"When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"5c7f76f56614738668266af7423e3104473c51b972a7f8a19b90b5099a3e8fe3","name":"MalCare WordPress Security Plugin &#8211; Malware Scanner, Cleaner, Security Firewall [malcare-security] < 6.72","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.72","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-84776","name":"CVE-2026-84776","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-84776","description":"[en] Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions.","date":"2026-09-03"},{"id":"af00eb98854bb99a45de3978299eda8d24d2509a","name":"MalCare WordPress Security Plugin \u2013 Malware Scanner, Cleaner, Security Firewall <= 6.69 - Unauthenticated Denial of Service","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/malcare-security\/malcare-wordpress-security-plugin-malware-scanner-cleaner-security-firewall-669-unauthenticated-denial-of-service","description":"The MalCare WordPress Security Plugin \u2013 Malware Scanner, Cleaner, Security Firewall plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 6.69. This is due to insufficient validation of user supplied input. This makes it possible for unauthenticated attackers to make the affected site unavailable.","date":"2026-08-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"n","a":"h","score":"7.5","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"none","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-770","name":"Allocation of Resources Without Limits or Throttling","description":"The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1789024854"}