The WP Remote WordPress Plugin, Malcare Security, and BlogVault Backup & Staging < 6.65 - Unauthenticated Site Takeover via Brute Force
criticalMultiple plugins for WordPress are vulnerable to unauthenticated site takeover in various versions. This is due to a weak pseudo-random number generator that makes it possible for attackers to brute force and connect to the remote connection feature. This makes it possible for unauthenticated attackers to connect a s...
- CVSS:
- 9.8 (Wordfence)
- Affected:
- up to 6.65
- Fixed in:
- 6.65
- Disclosed:
- Aug 24, 2026