Impact
The vulnerability allows any unauthenticated web user to recover the secret that links a WordPress site to its remote management service. The secret is derived from a weak pseudo‑random number generator, meaning an attacker can guess or brute‑force it. Once the secret is known, the attacker gains full administrative control, able to modify content, install plugins, or exfiltrate data. This weakness maps to CWE‑287.
Affected Systems
Affected products are the BlogVault Backup & Staging, MalCare WordPress Security Plugin, and The WP Remote WordPress Plugin. Versions before 6.65 of each contain the flaw; users should verify their installed versions.
Risk and Exploitability
Based on the description, it is inferred that the attack can be performed without authentication by accessing specific HTTP endpoints exposed by the plugins. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 8.1 indicates high severity, and because the secret is produced with a weak generator, the effort required to discover it is low, increasing the likelihood of successful exploitation when an attacker targets sites that use these plugins.
OpenCVE Enrichment