---
id: CVE-2026-96896
title: >-
  The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before
  19.9.7 does not perform an authorisation check on one of its AJAX actions,
  allowing users with a subsite administrator role on a multisite network to
  write and…
summary: >-
  The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before
  19.9.7 does not perform an authorisation check on one of its AJAX actions,
  allowing users with a subsite administrator role on a multisite network to
  write and…
severity: none
cwe:
  - CWE-862
product: 'Malcure Malware Shield — Removal, Repair, Monitor'
affected:
  - malcure_malware_shield_removal_repair_monitor < 19.9.7
published: '2026-09-27'
updated: '2026-09-27'
sourceUpdated: '2026-09-27T06:17:22.817'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96896'
references:
  - url: 'https://wpscan.com/vulnerability/7ab467f9-4340-464c-a436-978a5acbad3a/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-27T06:43:46.833Z'
---

## Overview

The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and delete arbitrary files in the network's shared filesystem, which can lead to remote code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
