Skip to content

Defender Security – Malware Scanner, Login Security & Firewall < 6.2.0

Wordfence September 2, 2026

As a reminder, the Wordfence Intelligence Vulnerability Database API is completely free to query and utilize, both personally and commercially, and contains all the same vulnerability data as the user interface. Please review the API documentation and Webhook documentation for more information on how to query the vulnerability API endpoints and configure webhooks utilizing all the same data present in the Wordfence Intelligence user interface.

The Defender Security – Malware Scanner, Login Security & Firewall plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 6.2.0. This is due to insufficient validation of user supplied input before it is executed. This makes it possible for authenticated attackers, with administrator-level access and above, to execute arbitrary code on the server.

plugins.trac.wordpress.org

Vulnerability Details for Defender Security – Malware Scanner, Login Security & Firewall

Defender Security – Malware Scanner, Login Security & Firewall

Recent vulnerabilities in Defender Security – Malware Scanner, Login Security & Firewall

This record contains material that is subject to copyright.

-2026 Defiant Inc.

-2026 The MITRE Corporation

Have information to add, or spot any errors? us at wfi-support@wordfence.com so we can make any appropriate adjustments.

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Want to get notified of the latest vulnerabilities that may affect your WordPress site? Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Extracted Entities

Domains (1)