Malcure Malware Shield < 19.9.7 - Multisite Subsite Admin+ Arbitrary File Write and Deletion via wpmr_ajax_request
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 7.2epss 0.4%
exploitation probability
0.4%top 69% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and delete arbitrary files in the network's shared filesystem, which can lead to remote code execution.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · Malcure Malware Shield — Removal, Repair, Monitorpublic PoCs found — 1
cve_referencewpscan.com/vulnerability/7ab467f9-4340-464c-a436-978a5acbad3a/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.