CVE-2026-84776
moderateUnauthenticated Denial-of-Service in MalCare Security WordPress plugin (<= 6.69)
CVE-2026-84776 is an unauthenticated denial-of-service flaw (CWE-770, allocation of resources without limits or throttling) in the MalCare Security WordPress plugin in versions up to and including 6.69. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates a remote attacker can trigger it with crafted network requests, without credentials or user interaction, causing resource exhaustion on the host. The impact is availability-only (C:N/I:N/A:H), so an attacker can knock a site offline or degrade performance but cannot read or modify data. Any WordPress site running MalCare Security 6.69 or older is affected. No public proof-of-concept or in-the-wild exploitation is known; EPSS is low (0.3% over 30 days) and the issue is not in CISA's KEV.
What to do: Update MalCare Security to the latest release above version 6.69 and verify the installed version under Plugins in wp-admin. Until patched, WAF or rate-limiting rules that throttle unauthenticated requests to the site can reduce the resource-exhaustion risk. Given no known exploitation and low EPSS, this can follow a normal patch cycle rather than emergency response.
| MalCare (BlogVault) MalCare Security (WordPress security plugin) | <= 6.69 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-770
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.