SECURITYHIGHCVE-2026-96896

Malcure Malware Shield Missing Authorization Enables Multisite File Write (CVE-2026-96896)

Malcure Malware Shield lacks an auth check on an AJAX action, letting subsite admins write or delete files network-wide on multisite.

Dylan H.

Security Team

September 27, 2026
4 min read
Malcure Malware Shield Missing Authorization Enables Multisite File Write (CVE-2026-96896)

Affected Products

  • Malcure Malware Shield — Removal, Repair, Monitor (wp-malware-removal), before 19.9.7, WordPress multisite networks

Executive Summary

A missing authorization vulnerability (CVE-2026-96896) has been disclosed in Malcure Malware Shield — Removal, Repair, Monitor, a WordPress security plugin with 10,000+ active installations. One of the plugin's AJAX actions does not perform an authorization check, meaning a user who holds only a subsite administrator role on a WordPress multisite network — not the network's super-admin — can call it to write or delete arbitrary files anywhere in the network's shared filesystem. On a multisite install, subsite admins are ordinarily confined to their own site; this flaw breaks that boundary and can lead to remote code execution if an attacker writes a malicious file into an executable location.

CVSS Score: 7.2 (High, CVSS 3.1)


Vulnerability Overview

AttributeValue
CVE IDCVE-2026-96896
CVSS Score7.2 (High), CVSS 3.1 vector AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
TypeMissing Authorization (CWE-862)
ScopeWordPress multisite networks only
Privileges RequiredHigh — subsite administrator role (not network super-admin)
Attack VectorNetwork (authenticated AJAX action)
Public ExploitNot observed as of publication
AssignerWPScan (CVE reserved 2026-09-23)
Published2026-09-27

Notably, this vulnerability is disclosed in a plugin whose stated purpose is malware removal — a broader third-party review separately flagged a recurring pattern of AJAX handlers in the plugin lacking authorization checks.


Affected Products

PluginAffected VersionsFixed VersionInstall Base
Malcure Malware Shield — Removal, Repair, Monitor (wp-malware-removal)Before 19.9.719.9.710,000+ active installs

Technical Details

Root Cause

The vulnerable AJAX action is intended to support the plugin's malware-scanning and file-repair features, which legitimately need filesystem write access to quarantine or restore files. The handler validates that the caller is authenticated and holds an administrator-level role, but it does not distinguish between a network super-admin and a subsite administrator — a much more common and lower-trust role on any multisite install with self-service or delegated site management. Because the underlying file operations target the network's shared filesystem rather than being scoped to the calling site, a subsite admin inherits capabilities that should be reserved for the network operator.

Attack Chain

1. Attacker holds (or compromises) a subsite administrator account
   on a WordPress multisite network running a vulnerable version
   of Malcure Malware Shield
 
2. Attacker calls the vulnerable AJAX action directly, supplying
   a target path outside their own site's directory
 
3. The handler performs the requested file write or delete without
   verifying the caller is a network super-admin
 
4. Attacker writes a malicious PHP file into a web-accessible,
   executable location shared across the network — or deletes
   files belonging to other sites on the network

Impact Assessment

Impact AreaDescription
Cross-Site Privilege EscalationSubsite admins gain effective control over files belonging to the entire network, not just their own site
Remote Code Execution PathWriting a PHP webshell to a shared, executable directory can lead to full server compromise
Data LossThe same missing check allows arbitrary file deletion, which can be used to sabotage other sites on the network
Ironic ExposureThe flaw exists in a plugin marketed for malware removal, which typically holds elevated filesystem trust

Recommendations

Immediate Actions

  1. Update Malcure Malware Shield to version 19.9.7 or later on every site in the network.
  2. Review subsite administrator accounts on any multisite network running this plugin — treat them as a broader trust boundary until patched.
  3. Audit the shared filesystem for unexpected PHP files, particularly in upload directories and other web-accessible paths, following the disclosure window.
  4. Restrict who can hold subsite administrator roles as a general multisite hardening practice, independent of this specific CVE.

Detection

  • Review server and application logs for AJAX requests to the plugin's file-management actions originating from subsite-admin accounts targeting paths outside their own site.
  • Run a file-integrity scan across the entire multisite shared filesystem, not just the site where suspicious activity was first noticed.

References