Description
Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions.
Published: 2026-09-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated denial of service vulnerability exists in MalCare Security plugin versions 6.69 and earlier. The flaw allows an attacker to trigger resource exhaustion or application, potentially rendering the WordPress site unavailable. The weakness is categorized as an allocation of resources problem (CWE‑770).

Affected Systems

WordPress sites running the MalCare Security plugin at version 6.69 or earlier are affected. The issue is fixed in version 6.72 and later, so any installation using those earlier releases is vulnerable.

Risk and Exploitability

The CVSS score of 7.5 indicates a high impact attack that requires no authentication; plugin can be accessed by anyone visiting the site. The EPSS score is not available, but because the vulnerability is remotely exploitable through web traffic, the likelihood of exploitation in the wild is inferred to be significant. The vulnerability is not listed in the CISA KEV catalog, so there is no known active exploitation campaign at this time, but the potential for a surge of automated attacks remains. An attacker could exploit the flaw to trigger resource exhaustion in the plugin, potentially causing the WordPress site to become unavailable.

Generated by OpenCVE AI on September 3, 2026 at 20:32 UTC.

Remediation

Vendor Solution

Update the WordPress MalCare Security plugin to the latest available version (at least 6.72).


OpenCVE Recommended Actions

  • Update the MalCare Security plugin to version 6.72 or later.
  • Apply rate limiting or firewall rules to restrict access to the plugin’s endpoints.
  • Monitor site logs for repeated requests to the plugin endpoints and block offending IPs if necessary.

Generated by OpenCVE AI on September 3, 2026 at 20:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions.
Title WordPress MalCare Security plugin <= 6.69 - Denial of Service Attack vulnerability
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-04T13:42:39.569Z

Reserved: 2026-09-02T09:57:48.859Z

Link: CVE-2026-84776

cve-icon Vulnrichment

Updated: 2026-09-04T13:28:14.670Z

cve-icon NVD

Status : Deferred

Published: 2026-09-03T17:17:28.507

Modified: 2026-09-04T14:17:20.923

Link: CVE-2026-84776

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T20:45:05Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling