PT-2026-81955 · WordPress · Blogvault Backup & Staging+2

·

CVE-2026-19718

·

Published

2026-08-26

·

Updated

2026-08-26

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BlogVault Backup & Staging WordPress plugin versions prior to 6.65 MalCare WordPress Security Plugin versions prior to 6.65 The WP Remote WordPress Plugin versions prior to 6.65
Description These plugins fail to prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service. Additionally, the secret is generated using a weak pseudo-random number generator, which allows attackers to recover the secret and gain administrative access to the site.
Recommendations Update BlogVault Backup & Staging WordPress plugin to version 6.65 or later. Update MalCare WordPress Security Plugin to version 6.65 or later. Update The WP Remote WordPress Plugin to version 6.65 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19718

Affected Products

Blogvault Backup & Staging
Malcare Wordpress Security Plugin
The Wp Remote