Executive Summary
A missing authorization vulnerability (CVE-2026-96896) has been disclosed in Malcure Malware Shield — Removal, Repair, Monitor, a WordPress security plugin with 10,000+ active installations. One of the plugin's AJAX actions does not perform an authorization check, meaning a user who holds only a subsite administrator role on a WordPress multisite network — not the network's super-admin — can call it to write or delete arbitrary files anywhere in the network's shared filesystem. On a multisite install, subsite admins are ordinarily confined to their own site; this flaw breaks that boundary and can lead to remote code execution if an attacker writes a malicious file into an executable location.
CVSS Score: 7.2 (High, CVSS 3.1)
Vulnerability Overview
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-96896 |
| CVSS Score | 7.2 (High), CVSS 3.1 vector AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| Type | Missing Authorization (CWE-862) |
| Scope | WordPress multisite networks only |
| Privileges Required | High — subsite administrator role (not network super-admin) |
| Attack Vector | Network (authenticated AJAX action) |
| Public Exploit | Not observed as of publication |
| Assigner | WPScan (CVE reserved 2026-09-23) |
| Published | 2026-09-27 |
Notably, this vulnerability is disclosed in a plugin whose stated purpose is malware removal — a broader third-party review separately flagged a recurring pattern of AJAX handlers in the plugin lacking authorization checks.
Affected Products
| Plugin | Affected Versions | Fixed Version | Install Base |
|---|---|---|---|
Malcure Malware Shield — Removal, Repair, Monitor (wp-malware-removal) | Before 19.9.7 | 19.9.7 | 10,000+ active installs |
Technical Details
Root Cause
The vulnerable AJAX action is intended to support the plugin's malware-scanning and file-repair features, which legitimately need filesystem write access to quarantine or restore files. The handler validates that the caller is authenticated and holds an administrator-level role, but it does not distinguish between a network super-admin and a subsite administrator — a much more common and lower-trust role on any multisite install with self-service or delegated site management. Because the underlying file operations target the network's shared filesystem rather than being scoped to the calling site, a subsite admin inherits capabilities that should be reserved for the network operator.
Attack Chain
1. Attacker holds (or compromises) a subsite administrator account
on a WordPress multisite network running a vulnerable version
of Malcure Malware Shield
2. Attacker calls the vulnerable AJAX action directly, supplying
a target path outside their own site's directory
3. The handler performs the requested file write or delete without
verifying the caller is a network super-admin
4. Attacker writes a malicious PHP file into a web-accessible,
executable location shared across the network — or deletes
files belonging to other sites on the networkImpact Assessment
| Impact Area | Description |
|---|---|
| Cross-Site Privilege Escalation | Subsite admins gain effective control over files belonging to the entire network, not just their own site |
| Remote Code Execution Path | Writing a PHP webshell to a shared, executable directory can lead to full server compromise |
| Data Loss | The same missing check allows arbitrary file deletion, which can be used to sabotage other sites on the network |
| Ironic Exposure | The flaw exists in a plugin marketed for malware removal, which typically holds elevated filesystem trust |
Recommendations
Immediate Actions
- Update Malcure Malware Shield to version 19.9.7 or later on every site in the network.
- Review subsite administrator accounts on any multisite network running this plugin — treat them as a broader trust boundary until patched.
- Audit the shared filesystem for unexpected PHP files, particularly in upload directories and other web-accessible paths, following the disclosure window.
- Restrict who can hold subsite administrator roles as a general multisite hardening practice, independent of this specific CVE.
Detection
- Review server and application logs for AJAX requests to the plugin's file-management actions originating from subsite-admin accounts targeting paths outside their own site.
- Run a file-integrity scan across the entire multisite shared filesystem, not just the site where suspicious activity was first noticed.