ZeroHour

CVE-2026-84776

moderate

Unauthenticated Denial-of-Service in MalCare Security WordPress plugin (<= 6.69)

CVSS 3.1
7.5 high
EPSS
<1%p18
Published
()
Modified
AI analysis

CVE-2026-84776 is an unauthenticated denial-of-service flaw (CWE-770, allocation of resources without limits or throttling) in the MalCare Security WordPress plugin in versions up to and including 6.69. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates a remote attacker can trigger it with crafted network requests, without credentials or user interaction, causing resource exhaustion on the host. The impact is availability-only (C:N/I:N/A:H), so an attacker can knock a site offline or degrade performance but cannot read or modify data. Any WordPress site running MalCare Security 6.69 or older is affected. No public proof-of-concept or in-the-wild exploitation is known; EPSS is low (0.3% over 30 days) and the issue is not in CISA's KEV.

What to do: Update MalCare Security to the latest release above version 6.69 and verify the installed version under Plugins in wp-admin. Until patched, WAF or rate-limiting rules that throttle unauthenticated requests to the site can reduce the resource-exhaustion risk. Given no known exploitation and low EPSS, this can follow a normal patch cycle rather than emergency response.

Affected
MalCare (BlogVault) MalCare Security (WordPress security plugin)<= 6.69
Estimated exposure
moderate~30,000-40,000 WordPress sites (plugin active-install count on WordPress.org) — Estimate based on the plugin's publicly listed active-install count on WordPress.org, which has been in the tens of thousands; only installations running version 6.69 or older are exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions.

Ecosystems
WordPress
Weakness
CWE-770
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.