PT-2025-30009 · WordPress · Malcure Malware Scanner

Arkadiusz Hydzik

·

Published

2025-07-18

·

Updated

2025-07-18

·

CVE-2025-7772

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress versions prior to 16.9
Description The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary File Read due to a missing capability check in the wpmr inspect file() function. This allows authenticated attackers with subscriber-level access or above to read the contents of arbitrary files on the server, potentially exposing sensitive information.
Recommendations Update to version 16.9 or later. As a temporary workaround, restrict access for users with subscriber-level access and above.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-7772

Affected Products

Malcure Malware Scanner