Segurium Research Advisories malcare-security
CVE-2026-19718: MalCare before 6.65
Before 6.65, BlogVault, MalCare and WP Remote built the secret that binds a site to their remote management service with a weak random number generator, and leaked data derived from it to unauthenticated callers. CVE-2026-19718, CVSS 8.1.
- Plugin
- MalCare
malcare-security - Affected versions
- before 6.65
- Fixed in
6.65- Class
- Authentication bypass
- Severity
- high CVSS 8.1
- CVE
- CVE-2026-19718
- Installs
- 200,000 active
- Patch released
- Sources