WordPress Security Alert: CVE-2025-6043 Enables Remote File Deletion via Malcure Plugin

Post Reply
Shane1145
Posts: 1854
Joined: Wed Sep 25, 2024 2:31 pm

WordPress Security Alert: CVE-2025-6043 Enables Remote File Deletion via Malcure Plugin

Post by Shane1145 »

A new vulnerability, CVE-2025-6043, has been discovered in the Malcure Malware Scanner plugin for WordPress, a popular security tool used by over 10,000 websites to detect and remove malware. Security researchers from Wordfence disclosed this flaw on July 15, 2025, identifying it as a high-severity issue rated 8.1 on the CVSS scale. The vulnerability, tracked under CVE-2025-6043, remains unpatched as of July 16, 2025.

https://thecyberexpress.com/malcure-vul ... 2025-6043/
Post Reply