{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-96896","assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","state":"PUBLISHED","assignerShortName":"WPScan","dateReserved":"2026-09-23T19:51:13.367Z","datePublished":"2026-09-27T06:00:22.286Z","dateUpdated":"2026-09-27T06:00:22.286Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan","dateUpdated":"2026-09-27T06:00:22.286Z"},"title":"Malcure Malware Shield < 19.9.7 - Multisite Subsite Admin+ Arbitrary File Write and Deletion via wpmr_ajax_request","problemTypes":[{"descriptions":[{"description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}]}],"affected":[{"vendor":"Unknown","product":"Malcure Malware Shield — Removal, Repair, Monitor","versions":[{"status":"affected","versionType":"semver","version":"0","lessThan":"19.9.7"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and delete arbitrary files in the network's shared filesystem, which can lead to remote code execution."}],"references":[{"url":"https://wpscan.com/vulnerability/7ab467f9-4340-464c-a436-978a5acbad3a/","tags":["exploit","vdb-entry","technical-description"]}],"credits":[{"lang":"en","value":"Charles Vosburgh","type":"finder"},{"lang":"en","value":"WPScan","type":"coordinator"}],"source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"WPScan CVE Generator"}}}}