BlogVault, MalCare and WP Remote 5.16 - 6.62 - Unauthenticated Site Takeover via Connection Key Recovery
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.1epss 0.3%
exploitation probability
0.3%top 79% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service, and generate that secret with a weak pseudo-random number generator, allowing attackers to recover it and gain administrative access to the site.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · BlogVault Backup & StagingUnknown · MalCare WordPress Security PluginUnknown · The WP Remote WordPress Pluginpublic PoCs found — 1
cve_referencewpscan.com/vulnerability/68892d43-912d-421f-9376-8dc6e2e906bc/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.