Unrated severityNVD Advisory· Published Sep 27, 2026
CVE-2026-96896
CVE-2026-96896
Description
The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and delete arbitrary files in the network's shared filesystem, which can lead to remote code execution.
Affected products
1- Range: <19.9.7
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.