CVE-2026-19718

BlogVault · BlogVault Backup & Staging, MalCare WordPress Security Plugin, and The WP Remote WordPress Plugin

Multiple WordPress plugins from BlogVault fail to secure site-to-remote secret generation, allowing unauthenticated attackers to recover secrets and obtain administrative access to affected sites.

Executive summary

An unauthenticated administrative access vulnerability in BlogVault, MalCare, and WP Remote plugins poses a critical risk to site integrity and data security.

Vulnerability

The vulnerability stems from improper authentication and the use of a weak pseudo-random number generator to create site binding secrets. This flaw allows unauthenticated remote attackers to derive or recover these secrets, effectively bypassing authentication mechanisms to gain full administrative control over the WordPress instance.

Business impact

The ability for an unauthenticated attacker to gain administrative access represents a total compromise of the WordPress environment. This could lead to the theft of sensitive site data, the injection of malicious code, or complete site defacement and downtime. Given the CVSS score of 8.1, the potential for widespread exploitation of these popular plugins necessitates immediate intervention to prevent severe operational and reputational damage.

Remediation

Immediate Action: Update all affected plugins (BlogVault Backup & Staging, MalCare, and The WP Remote) to version 6.65 or later immediately.

Proactive Monitoring: Review WordPress administrative access logs for unusual login activity or suspicious account creations during the period prior to patching.

Compensating Controls: While a Web Application Firewall cannot fully replace the need for a patch, it may help block common attack patterns targeting administrative endpoints until the update is deployed.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability is highly severe due to its potential for full administrative takeover without requiring prior authentication. Organizations utilizing these plugins must prioritize the update to version 6.65 across all managed WordPress sites. Failure to patch these components leaves the infrastructure exposed to complete unauthorized control and data exfiltration.

Sources

Originally found and disclosed by Jakub Herman, with WPScan (coordinator), per the CVE Program record.