Skip to content
August 19, 2025

Free Websites, share News and Posts publicly

Primary Menu
  • Registration free websites/as writer
  • Login
Live
  • Home
  • [New post] MalCare, Blogvault, and WPRemote Plugins Patch Vulnerabilities Allowing Site Takeover Through Stolen API Credentials
  • news

[New post] MalCare, Blogvault, and WPRemote Plugins Patch Vulnerabilities Allowing Site Takeover Through Stolen API Credentials

alisa July 11, 2023 3 min read
Site logo image Sarah Gooding posted: ”  Snicco, a WordPress security services provider, has published an advisory on a vulnerability in the MalCare plugin, which is active on more than 300,000 sites. “MalCare uses broken cryptography to authenticate API requests from its remote servers to” WP Tavern

MalCare, Blogvault, and WPRemote Plugins Patch Vulnerabilities Allowing Site Takeover Through Stolen API Credentials

0bce5db7a60aebfe02859e1f166195737a6a823d6aaa45dfaccc668744d804d0?s=96&d=retro&r=R

Sarah Gooding

Jul 10

 Snicco, a WordPress security services provider, has published an advisory on a vulnerability in the MalCare plugin, which is active on more than 300,000 sites.

“MalCare uses broken cryptography to authenticate API requests from its remote servers to connected WordPress sites,” WordPress security researcher Calvin Alkan said.

“Requests are authentication by comparing a shared secret stored as plaintext in the WordPress database to the one provided by MalCare’s remote application.

“This can allow attackers to completely take over the site because they can impersonate MalCare’s remote application and perform any implemented action.”

These potential malicious actions include creating rogue admin users, uploading random files to the site, and installing and removing plugins.

Exploitation requires a pre-condition to be met, such as a site with a SQL injection vulnerability in a plugin, theme, or WordPress core, or a database compromised at the hosting level, or subject to another vulnerability that allows the attacker to read or update WordPress options.

“MalCare has received the full details of this vulnerability three months before this public release, and despite us offering (free) help, they subtly dismissed it because ‘supposedly’ this is the industry standard for API authentication,” Alkan said.

“Furthermore, concerns were raised, because the vulnerability requires a pre-condition that on its own, would be a vulnerability.”

Two days after Snicco published the security advisory with the proof of concept, MalCare pushed a patch in version 5.16 on July 8, 2023, along with a notice on the plugin’s blog:

In the rare situation, where a site has a pre-existing, high severity SQL injection vulnerability, an attacker might be able to read the MalCare key. To address such issues, we are further strengthening our authentication systems.

Authentication is a critical system and any improvements must be done in a careful manner. We have reviewed various plugins and best practices in our ecosystem to come up with our solution.

In light of the current public discourse, we are expediting the update of our plugin. We will initiate a rollout by EOD.

MalCare reports that its users have seen no evidence of the vulnerability being exploited.

Snicco noted that the same vulnerability also exists in WPRemote (20k installs) and Blogvault (100k installs) plugins, as they share the same code. Users of either of these plugins or the MalCare plugin should update to the latest versions as soon as possible now that the vulnerability advisory and proof of concept have been published.

Comment

Unsubscribe to no longer receive posts from WP Tavern.
Change your email settings at manage subscriptions.

Trouble clicking? Copy and paste this URL into your browser:
https://wptavern.com/malcare-blogvault-and-wpremote-plugins-patch-vulnerabilities-allowing-site-takeover-through-stolen-api-credentials

WordPress.com and Jetpack Logos

Get the Jetpack app to use Reader anywhere, anytime

Follow your favorite sites, save posts to read later, and get real-time notifications for likes and comments.

Download Jetpack on Google Play Download Jetpack from the App Store
WordPress.com on Twitter WordPress.com on Facebook WordPress.com on Instagram WordPress.com on YouTube
WordPress.com Logo and Wordmark title=

Automattic, Inc. – 60 29th St. #343, San Francisco, CA 94110  

t.gif?has featured image=0&subscriber id=530390941& ui=8ba62ef4a9e9a49d3fe3da3d5a99ce4d& ut=anon&email domain=gmail.com&blog id=9006382&post id=146708&date sent=2023 07 11&email id=2dc151a2e36b7af179214cdb347dcf34&email name=new post&template=new post& en=wpcom email open&browser type=php agent& aua=wpcom tracks client v0b.gif?blog=9006382&post=146708&subd=wptavern.com&ref=&email=1&email o=jetpack&host=wptavern

Chat read-only to anonymous users. Chat with Anyone and Anywhere. Only registered users are allowed to send messages.
Loading the chat ...
102995 Register Login

Continue Reading

Previous: President Xi receives honorary doctorate from King Saud University – MFA China
Next: Trump opposes quick trial date in classified documents case

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

verde two
VERDE TWO Apartment sale
  • actress and actor
  • Afghanistan
  • airlines
  • amazon
  • America
  • android
  • apache
  • apple
  • Arab
  • australia
  • Australian Embassy
  • automotive
  • bahan bangunan
  • Bali island
  • Ban
  • banking
  • bearing
  • Brazil
  • Brunei Darussalam
  • business
  • canada
  • casino
  • China
  • cloud
  • cloudflare
  • cPanel
  • cruise
  • crypto currency
  • culture
  • currency
  • DNS
  • docker
  • eCommerce
  • economy
  • education
  • Email
  • Energy
  • england
  • entertainment
  • environment
  • Fashion
  • finance
  • Food
  • France
  • gaming
  • garden
  • Germany
  • golf
  • Golf indonesia
  • google
  • HarmonyOS
  • Health products
  • history
  • hospital
  • hotel restaurant
  • Huawei
  • human
  • IBM
  • IMF
  • india
  • Indonesia
  • instagram
  • internet
  • investment
  • Israel
  • Japan
  • jobs
  • kitchenware
  • korea
  • kubernetes
  • KVM
  • Leisure
  • limbah
  • Linux
  • Living style
  • Longhorn
  • lottery
  • machine
  • machine learning
  • machinery
  • Malaysia
  • manufacturing
  • mariadb
  • maritime
  • material building
  • medical
  • meta
  • Microsoft
  • music
  • MySQL
  • New Zealand
  • news
  • NFS
  • Nickel
  • nightclub
  • north korea
  • OBS
  • oil and gas
  • Pakistan
  • Palestine
  • Philippines
  • Photography
  • php
  • phpMyAdmin
  • private-jet
  • promotion products
  • real estate
  • Resort hotel
  • Russia
  • sanitary ware
  • search engine
  • Shopping Mal
  • singapore
  • Singapore Pools
  • software
  • south korea
  • sport
  • ssl
  • swiss
  • Technology
  • Thailand
  • tourism boards
  • travel
  • Turkish
  • Ubuntu
  • Uncategorized
  • United Arab Emirates
  • vietnam
  • virtualbox
  • virtualization
  • vmware
  • water products
  • whatsapp
  • WordPress
Register and posting news , your skills , knowledge , science , stories , experiences , etc
Copyright © All rights reserved. The tiatira is not responsible for the content of each writer / author , external sites. |