A WordPress malware-scanner plugin has an RCE bug of its own
Malcure Malware Shield, installed on more than 10,000 sites, patched a missing-authorization flaw that let multisite subsite admins write and delete arbitrary files, with a path to remote code execution.
Malcure Malware Shield — Removal, Repair, Monitor, a WordPress plugin whose whole job is catching malware on your site, patched a remote code execution bug in itself on 27 September. It’s installed on more than 10,000 sites.
The flaw, CVE-2026-96896, is a missing authorization check (CWE-862) on one of the plugin’s AJAX actions. On a WordPress multisite network, any user with a subsite administrator role, someone who only manages one site in the network, could use that action to write and delete arbitrary files in the network’s shared filesystem. On a stack that will execute PHP from that location, that’s remote code execution from an account that was never meant to touch anything outside its own subsite. Every version before 19.9.7 is affected; 19.9.7 adds the missing check.
Why it matters: if you run WordPress multisite and hand subsite administration to people or teams you don’t fully trust with the whole network, this is exactly the kind of privilege boundary that needs to hold. Update now that the fix exists.
The caveat: it only bites on multisite networks with subsite admins, a single-site install isn’t exposed. No CVSS score has been assigned yet and there’s no sign of active exploitation, but the technical detail is already public.