Sceawere
Vulnerability Detail
CVE-2026-96896UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Malcure Malware Shield Unauthorized File Manipulation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 1d ago
- Vendor
- Unknown
- Product
- Malcure Malware Shield — Removal, Repair, Monitor
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and delete arbitrary files in the network's shared filesystem, which can lead to remote code execution.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-09-27T06:17:22.817Z",
"pubdate": "2026-09-27T06:17:22.817Z",
"executiveSummary": "The Malcure Malware Shield WordPress plugin, in versions prior to 19.9.7, contains a critical security vulnerability involving improper authorization on an AJAX action. This flaw allows a user authenticated as a subsite administrator within a WordPress multisite network to perform unauthorized file operations, specifically the ability to write to or delete arbitrary files within the network's shared filesystem.\nThis vulnerability is classified as an authorization bypass, which effectively escalates the privileges of a subsite administrator to perform administrative actions on the shared filesystem. The primary impact is potential Remote Code Execution (RCE) and full compromise of the affected WordPress environment. Attackers can leverage this capability to upload malicious web shells, modify core configuration files, or disrupt site operations by deleting critical system files.\nExploitation requires the attacker to have at least a subsite administrator account on the multisite installation. Given the nature of WordPress multisite environments where subsite admins are often considered untrusted, this vulnerability poses a severe risk to the entire network integrity. No specific external network exposure beyond the standard WordPress administrative interface is required for successful exploitation.",
"technicalDetails": "The root cause of this vulnerability lies in the missing implementation of capability checks within an AJAX handler managed by the Malcure Malware Shield plugin. WordPress AJAX actions defined via 'wp_ajax_' hooks are intended to be secured by explicit verification of the current user's role and capabilities using functions such as 'current_user_can()'. In the affected versions prior to 19.9.7, the plugin fails to enforce these checks when processing incoming AJAX requests.\nThe attack flow initiates when an authenticated subsite administrator submits a crafted request to the plugin's insecure AJAX action. Because the server-side code does not validate whether the requesting user possesses the necessary 'manage_network' or 'administrator' privileges, the server proceeds to execute the requested file manipulation operation with the elevated permissions of the web server process.\nThe vulnerability enables arbitrary file system access. An attacker can supply parameters to the vulnerable AJAX endpoint to specify file paths, allowing for the deletion of system-critical files (such as wp-config.php or index.php) or the creation of new files. By injecting arbitrary PHP content into a reachable file or creating a new malicious script within the web-accessible directory, the attacker achieves Remote Code Execution (RCE). Once RCE is achieved, the attacker executes arbitrary system commands with the privileges of the web server user (e.g., www-data), leading to complete control over the application, the underlying server environment, and potentially the entire multisite network.\nThe scope of this vulnerability is particularly severe in a multisite context, as the 'shared filesystem' allows an attacker restricted to a single site instance to perform operations across the network boundaries. The failure to isolate these operations ensures that the subsite administrator can break out of their intended logical boundary and manipulate files belonging to the main site or other network sites. The absence of input sanitization combined with the missing authorization check makes the exploitation process trivial for an authenticated user with minimal technical knowledge."
}