Junglewise Threat Intelligence

CVE-2026-84776: MalCare Security unauthenticated denial of service

CVE-2026-84776 · Severity: high · CVSS 7.5 · Published 2026-09-03

Executive brief

MalCare Security is a WordPress security plugin used to protect websites from malware and attacks. An unauthenticated attacker can trigger a denial of service condition, causing the affected website to become slow or go offline without requiring any special credentials or valid user account.

Technical details

This vulnerability is a denial of service (DoS) attack in MalCare Security WordPress plugin versions 6.69 and earlier. The flaw allows an unauthenticated attacker to overwhelm or crash the affected site through a network-based attack vector. No authentication is required, making it trivially exploitable by remote attackers. The vulnerability has been patched in version 6.72. CVSS score is 7.5, reflecting high severity due to ease of exploitation and impact on site availability.

Affected products

  • Wordfence MalCare Security <=6.69

Timeline

  • 2026-09-03: disclosed
  • 2026-09-02: patched: Patched in version 6.72

References