Authorization Bypass in Malcure Malware Shield Plugin for WordPress
CVE-2026-96896

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 September 2026

Badges

πŸ‘Ύ Exploit Exists🟑 Public PoC

What is CVE-2026-96896?

The Malcure Malware Shield plugin for WordPress before version 19.9.7 is susceptible to an authorization bypass vulnerability. This flaw allows individuals with a subsite administrator role on a multisite WordPress network to perform AJAX actions without proper authorization checks. As a result, these users can write and delete arbitrary files within the shared filesystem of the network. This vulnerability poses a significant risk as it can potentially lead to remote code execution, allowing attackers to execute malicious code on the server.

Affected Version(s)

Malcure Malware Shield β€” Removal, Repair, Monitor 0 < 19.9.7

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Charles Vosburgh
WPScan
.