Segurium Research Advisories malcare-security

CVE-2026-19718: MalCare before 6.65

high 8.1 Authentication bypass

Before 6.65, BlogVault, MalCare and WP Remote built the secret that binds a site to their remote management service with a weak random number generator, and leaked data derived from it to unauthenticated callers. CVE-2026-19718, CVSS 8.1.

Plugin
MalCare malcare-security
Affected versions
before 6.65
Fixed in
6.65
Class
Authentication bypass
Severity
high CVSS 8.1
CVE
CVE-2026-19718
Installs
200,000 active
Patch released
Sources
Read the teardown What the release changed, how the bug worked, and what to check on a site that ran the affected version.

Segurium Research writes these up from public source after the fix has shipped. We do not scan or probe third-party sites, and no teardown here carries a working exploit. Segurium itself is a WordPress malware scanner on the official directory at wordpress.org/plugins/segurium/.