Malcure Malware Scanner WordPress Plugin Arbitrary File Read Vulnerability

Vulnerability

A vulnerability allowing arbitrary file read has been identified in the Malcure Malware Scanner WordPress plugin, in all versions through 16.8. The issue arises in the wpmr_inspect_file() function, where a missing capability check allows authenticated users with subscriber-level access and above to read arbitrary files on the server. This could lead to the exposure of sensitive information.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive file contents on the server.

Remediation

Users are advised to update the Malcure Malware Scanner WordPress plugin to version 16.9 or a newer patched version.

Added: Jul 18, 2025, 7:23 AM
Updated: Jul 18, 2025, 7:23 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.9
remediation
7.7
relevance
0.3
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.