
Vulnerability Reports
Dated disclosures of plugin, theme, and core vulnerabilities, and how MalCare responds.
34 articles · page 1 of 3


New cPanel Vulnerability Proves Malware Scanners Are No Longer Optional
Learn what CVE-2026-41940 means for cPanel-hosted WordPress sites and why continuous malware scanning is essential after a hosting-level breach.
Critical Bug in Ally Plugin Targets 400,000 Websites—Was Yours Affected?
A serious security flaw was found in the Ally WordPress plugin, a tool running on more than 400,000 websites. This wasn't a minor bug.
MalCare Blocks 11000+ Attacks on Royal Elementor Plugin v1.3.78 RCE Vulnerability Before Patch Release
MalCare blocked more than 11000 attempts to exploit the recently discovered Royal Elementor plugin vulnerability. Our firewall protected sites for over a week
MalCare Protects Against Massive LiteSpeed Cache Privilege Escalation Vulnerability
A critical LiteSpeed Cache privilege-escalation flaw affected millions of sites. Learn what happened and how MalCare protected customers.
MalCare’s Atomic Security Shields Sites From Critical GiveWP PHP Object Injection Vulnerability
A critical level 10 vulnerability in the GiveWP plugin has been discovered and patched. This issue impacted over 100,000 sites. Hackers could exploit it to
MalCare Defends Against Login/Signup Popup Privilege Escalation Vulnerability
A Login/Signup Popup flaw could let subscribers gain administrator access. Learn which versions were affected and how to protect your site.
Gravity Forms Bug Left 46,000+ Sites Exposed. Was Yours One of Them?
Understand the Gravity Forms arbitrary file-upload flaw, determine exposure, update safely, and check the site for compromise.
The Hidden Life of WordPress Vulnerabilities
Follow a WordPress vulnerability from discovery and disclosure through patching, exploitation, and practical site protection.
Clarifying the Elementor Arbitary File Upload Vulnerability
Recently, a security vulnerability in Elementor, a popular WordPress plugin, made headlines. Two databases rated its severity at a staggering 9.9 and 8.8.
MalCare Stands Strong Against Attacks Exploiting the Elementor Plugin v3.18.1 RCE Vulnerability
Recently, a critical vulnerability was discovered in the Elementor plugin, the popular page-building tool for WordPress. This vulnerability posed a
MalCare Blocks 1.2 Billion+ XSS Attacks Exploiting the tagDiv Plugin Vulnerability
MalCare recently blocked over 1.2 billion cross-site scripting (XSS) attacks on its customer websites. In the biggest attack campaign of the year, MalCare saw
A Tale of Two Vulnerabilities
When you see news of a 9.9 (or in some cases 8.8) vulnerability in Elementor, that is a cue to panic.