Skip to main content

CVE-2025-7772: Malcure Scanner Arbitrary File Read Vulnerability

CVE-2025-7772 is an arbitrary file read flaw in Malcure Malware Scanner plugin that allows authenticated attackers to access sensitive files. This article covers technical details, affected versions, security impact, and mitigation.

Published:

CVE-2025-7772 Overview

CVE-2025-7772 affects the Malcure Malware Scanner WordPress plugin in all versions up to and including 16.8. The vulnerability allows authenticated users with subscriber-level access to read arbitrary files on the server. The flaw resides in the wpmr_inspect_file() function, which lacks a capability check before serving file contents. Attackers can retrieve sensitive files including wp-config.php, which contains database credentials and authentication secrets. The vulnerability is tracked under CWE-862: Missing Authorization.

Critical Impact

Authenticated attackers with minimal privileges can read arbitrary server files, exposing credentials, API keys, and configuration data that enable further compromise of the WordPress site and backend database.

Affected Products

  • Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin
  • All versions up to and including 16.8
  • WordPress installations with authenticated subscriber accounts

Discovery Timeline

  • 2025-07-18 - CVE-2025-7772 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-7772

Vulnerability Analysis

The Malcure Malware Scanner plugin exposes the wpmr_inspect_file() function through an AJAX endpoint intended for administrators. The function reads and returns the contents of a file path supplied by the caller. The implementation performs no current_user_can() or equivalent capability check before executing the read operation.

Any authenticated user, including low-privilege subscribers, can invoke the endpoint and specify arbitrary file paths. The function returns the raw file contents in the HTTP response. This exposes files such as wp-config.php, /etc/passwd, backup archives, log files, and private keys readable by the web server user.

WordPress sites commonly allow open user registration at the subscriber role, which lowers the barrier to exploitation. The attack requires no social engineering or user interaction beyond initial account creation.

Root Cause

The root cause is a missing authorization check in the AJAX handler bound to wpmr_inspect_file(). The function registers with wp_ajax_ hooks that grant access to any logged-in user. Without an explicit capability verification, WordPress treats every authenticated session as authorized. The function also lacks path sanitization that would restrict reads to the plugin directory.

Attack Vector

An attacker registers or obtains a subscriber-level WordPress account. The attacker then sends a POST request to /wp-admin/admin-ajax.php with the action parameter targeting the vulnerable handler. The request includes a file path parameter pointing to the desired target file. The server executes the read and returns contents in the response body. Exfiltrating wp-config.php yields the DB_PASSWORD, AUTH_KEY, SECURE_AUTH_KEY, and other secrets that enable database access and session forgery.

Detection Methods for CVE-2025-7772

Indicators of Compromise

  • POST requests to /wp-admin/admin-ajax.php with action parameters referencing wpmr_inspect_file or related Malcure handlers.
  • HTTP responses from admin-ajax.php containing file paths such as wp-config.php, .htaccess, or /etc/passwd content signatures.
  • Subscriber-level accounts generating admin-ajax traffic patterns inconsistent with normal low-privilege behavior.
  • Unexpected read access to WordPress configuration files recorded in file integrity monitoring.

Detection Strategies

  • Inspect web server access logs for admin-ajax.php requests originating from non-administrator sessions with file-path parameters.
  • Deploy web application firewall rules that match the vulnerable action name and block requests from subscriber role sessions.
  • Correlate new user registrations followed by admin-ajax activity within short time windows as suspicious behavior.

Monitoring Recommendations

  • Enable WordPress audit logging to track AJAX actions invoked per user role.
  • Monitor outbound responses from admin-ajax.php for payload sizes anomalous for the expected endpoint.
  • Alert on any filesystem access to wp-config.php or credential files by the PHP worker process.

How to Mitigate CVE-2025-7772

Immediate Actions Required

  • Update the Malcure Malware Scanner plugin to a version later than 16.8 once the vendor publishes a patched release.
  • Audit WordPress user accounts and disable open subscriber registration if not required.
  • Rotate all secrets stored in wp-config.php including database credentials and WordPress authentication keys.
  • Review web server logs for prior exploitation attempts referencing the vulnerable AJAX action.

Patch Information

Review the WordPress Plugin Changeset and the Wordfence Vulnerability Report for remediation details and tracking of the fix.

Workarounds

  • Deactivate and remove the Malcure Malware Scanner plugin until a patched version is confirmed deployed.
  • Restrict access to /wp-admin/admin-ajax.php from untrusted networks using web server access controls where feasible.
  • Enforce strict role-based access policies and remove unused subscriber accounts.
  • Apply file system permissions that prevent the PHP worker from reading files outside the WordPress document root.
bash
# Configuration example: restrict admin-ajax access via nginx
location = /wp-admin/admin-ajax.php {
    allow 10.0.0.0/8;
    deny all;
    include fastcgi_params;
    fastcgi_pass php-fpm;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.