{"id":"CVE-2026-96896","title":"The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and…","summary":"The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and…","severity":"none","cwe":["CWE-862"],"product":"Malcure Malware Shield — Removal, Repair, Monitor","affected":["malcure_malware_shield_removal_repair_monitor < 19.9.7"],"published":"2026-09-27","updated":"2026-09-27","sourceUpdated":"2026-09-27T06:17:22.817","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-96896","references":[{"url":"https://wpscan.com/vulnerability/7ab467f9-4340-464c-a436-978a5acbad3a/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-27T06:43:46.833Z","slug":"CVE-2026-96896","body":"## Overview\n\nThe Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and delete arbitrary files in the network's shared filesystem, which can lead to remote code execution.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}