WordPress Malware Scanner Plugin Contains Vulnerability

Malcure Malware Scanner Plugin Vulnerability Exposes WordPress Sites to Risk
Photo: Search Engine Journal

Malcure Malware Scanner Plugin Vulnerability Exposes WordPress Sites to Risk

The Malcure Malware Scanner plugin, which has been installed on over 10,000 WordPress sites, contains a serious vulnerability that allows authenticated attackers to delete arbitrary files. The vulnerability, rated 8.1 in severity, is due to a missing capability check in the ‘wpmr_delete_file()’ function. While the vulnerability requires at least Subscriber-level authentication, which is the default for most WordPress sites, it still poses a significant risk, especially when advanced mode is enabled. The issue has been temporarily addressed by taking the plugin down from the WordPress repository, but no patch is available yet. Security experts, including Wordfence, have advised users to uninstall the plugin to avoid potential exploitation. The plugin was initially available on over 10,000 websites, making it a widespread concern for the WordPress community. Users are urged to take immediate action until a patch or fix is provided.

Leave a Reply

Your email address will not be published. Required fields are marked *