PT-2026-81955 · WordPress · Blogvault Backup & Staging+2
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BlogVault Backup & Staging WordPress plugin versions prior to 6.65
MalCare WordPress Security Plugin versions prior to 6.65
The WP Remote WordPress Plugin versions prior to 6.65
Description
These plugins fail to prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service. Additionally, the secret is generated using a weak pseudo-random number generator, which allows attackers to recover the secret and gain administrative access to the site.
Recommendations
Update BlogVault Backup & Staging WordPress plugin to version 6.65 or later.
Update MalCare WordPress Security Plugin to version 6.65 or later.
Update The WP Remote WordPress Plugin to version 6.65 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blogvault Backup & Staging
Malcare Wordpress Security Plugin
The Wp Remote