
We have removed a security risk in a rare edge case of our plugin connection process. If you’re a customer of BlogVault, MalCare, or WP Remote, please rest assured:
- No sites were impacted
- No update or action is required
No version of our plugin, even if it is older than 6.64, is affected by this issue anymore. We have deprecated the API that was needed for this issue. Hence, there is no risk to any site whatsoever.
Was your site affected?
No, simply having our plugins installed or having a site added to an account was not enough to put you at risk.
The vulnerable path only appeared when several conditions (shown in the next section) came together at the same time. Even then, an attacker had a short window to break an encrypted connection key before it expired automatically.
That being said, this is still a bug that we should have identified and removed earlier. We thank Jakub Herman from WPScan for identifying and working with us during the remediation process.
What was the issue?
Our plugins use a temporary, encrypted connection key to connect a site to an account. Normally, once the site is connected, the key is removed, or it auto-expires.
The vulnerable path existed if several things happened at the same time:
- The site was running an affected plugin version, from v5.16 through v6.64.
- The user visited the plugin-connection page in wp-admin and generated a temporary connection key.
- The user left without connecting the plugin or taking any other action.
- Our server had not yet completed the sync that removes the temporary key.
- The temporary key had not reached its automatic 24-hour expiration.
- The legacy server-side connection protocol was still accepting the old key.
In that specific scenario, they would be able to add that site to another account of their own.
No sites were impacted
We deprecated the server-side API related to this issue as soon as the issue was reported to us. This ensured that even if you have an older plugin in any form, you are not at risk. Furthermore, we’ve checked for other edge cases and strengthened our protocols.
If you have any questions or concerns, our support team is here to help you.



