PT-2025-29708 · WordPress · Malcure Malware Scanner — #1 Toolset For Wordpress Malware Removal

Arkadiusz Hydzik

·

Published

2025-07-15

·

Updated

2025-07-24

·

CVE-2025-6043

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress versions through 16.8
Description The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary File Deletion due to a missing capability check on the wpmr delete file() function. This allows authenticated attackers with Subscriber-level access or above to delete arbitrary files, potentially leading to remote code execution. This is only exploitable when advanced mode is enabled on the site.
Recommendations Versions prior to 16.9: Ensure a capability check is implemented within the wpmr delete file() function to restrict file deletion access to authorized users only. Versions prior to 16.9: Disable advanced mode on the site to prevent exploitation of the vulnerability.

Fix

RCE

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-16385
CVE-2025-6043

Affected Products

Malcure Malware Scanner — #1 Toolset For Wordpress Malware Removal