Answer in brief
CVE-2026-19718 records a Unknown severity vulnerability in BlogVault, MalCare and WP Remote 5.16 - 6.62 - Unauthenticated Site Takeover via Connection Key Recovery. The current sources do not mark it as known exploited. The current feed maps Unknown/BlogVault Backup & Staging (generic), Unknown/MalCare WordPress Security Plugin (generic), Unknown/The WP Remote WordPress Plugin (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Unknown/BlogVault Backup & Staging (generic), Unknown/MalCare WordPress Security Plugin (generic), Unknown/The WP Remote WordPress Plugin (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Unknown/BlogVault Backup & Staginggeneric | >=5.16 <6.65 | 6.65 |
| Unknown/MalCare WordPress Security Plugingeneric | >=5.16 <6.65 | 6.65 |
| Unknown/The WP Remote WordPress Plugingeneric | >=5.16 <6.65 | 6.65 |
Published upstream
Aug 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 26, 2026
The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service, and generate that secret with a weak pseudo-random number generator, allowing attackers to recover it and gain administrative access to the site.
Quoted source text, attributed separately from HOL analysis.