Malcure Malware Scanner WordPress Plugin Arbitrary File Read Vulnerability
Vulnerability
A vulnerability allowing arbitrary file read has been identified in the Malcure Malware Scanner WordPress plugin, in all versions through 16.8. The issue arises in the wpmr_inspect_file() function, where a missing capability check allows authenticated users with subscriber-level access and above to read arbitrary files on the server. This could lead to the exposure of sensitive information.
Impact
Exploitation of this vulnerability could result in unauthorized access to sensitive file contents on the server.
Remediation
Users are advised to update the Malcure Malware Scanner WordPress plugin to version 16.9 or a newer patched version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
