Impact
An unauthenticated denial of service vulnerability exists in MalCare Security plugin versions 6.69 and earlier. The flaw allows an attacker to trigger resource exhaustion or application, potentially rendering the WordPress site unavailable. The weakness is categorized as an allocation of resources problem (CWE‑770).
Affected Systems
WordPress sites running the MalCare Security plugin at version 6.69 or earlier are affected. The issue is fixed in version 6.72 and later, so any installation using those earlier releases is vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact attack that requires no authentication; plugin can be accessed by anyone visiting the site. The EPSS score is not available, but because the vulnerability is remotely exploitable through web traffic, the likelihood of exploitation in the wild is inferred to be significant. The vulnerability is not listed in the CISA KEV catalog, so there is no known active exploitation campaign at this time, but the potential for a surge of automated attacks remains. An attacker could exploit the flaw to trigger resource exhaustion in the plugin, potentially causing the WordPress site to become unavailable.
OpenCVE Enrichment