cleantalk
Vulnerabilities and Security Researches

MalCare WordPress Security Plugin – Malware Scanner, Cleaner, Security Firewall, PSC-2026-64632

PSC, Research URL

PSC-2026-64632

Published on
Mar 27, 2026
Research Description
Security plugins are uniquely sensitive in WordPress because they operate with high privilege, touch authentication and request filtering, and often integrate with external scanning and firewall services. If access control, request integrity, or output handling is weak, attackers may force configuration changes via CSRF, abuse endpoints to leak site security metadata, or inject malicious content into admin-facing reports. MalCare WordPress Security Plugin – Malware Scanner, Cleaner, Security Firewall version 6.39 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64632, confirming that the plugin was reviewed from a secure code perspective with attention to the most common exploitation paths for WordPress security and monitoring plugins.
Affected versions
Min 6.39, max 6.39.
Status
SAFE & CERTIFIED