rootpwn

critical · CVSS v3 8.8

CVE-2026-19807

The ByteCoreStack MCP Connector for AI Tools WordPress plugin has a privilege escalation flaw in its MCP user-meta update tool. It allows au

Overview

The ByteCoreStack MCP Connector for AI Tools WordPress plugin has a privilege escalation flaw in its MCP user-meta update tool. It allows authenticated low-privilege users to modify sensitive account metadata that controls role capabilities. This matters because it can turn a basic subscriber account into an administrator.

Description

The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the `wp_update_user_meta` MCP tool in `execute_tool` gating writes solely with `current_user_can('edit_user', $uid)` — a check that WordPress core's `map_meta_cap` resolves to the `read` primitive when the target user ID matches the caller's own — while enforcing an incomplete meta key blocklist that covers only `user_pass`, `user_activation_key`, and `session_tokens`, leaving the `wp_capabilities` and `wp_user_level` meta keys entirely unprotected. This makes it possible for authenticated attackers with Subscriber-level access and above to elevate their privileges to Administrator by issuing a `wp_update_user_meta` call over the MCP JSON-RPC endpoint with `key=wp_capabilities` and an arbitrary role array such as `{'administrator': true}` targeting their own user ID, causing WordPress to load that account as an Administrator on the next request.

Impact

Confidentiality and integrity are affected because an attacker can gain administrative control over a WordPress site. Availability may be impacted if the compromised account is used to alter site configuration, content, or user accounts. WordPress sites running the vulnerable plugin are impacted, especially those exposing the MCP endpoint to authenticated users with Subscriber-level or higher access. The risk is higher where the plugin is used in production or connected to AI tooling that can invoke MCP tools.

Remediation

Apply a vendor patch if released; if no patched version is available, disable or remove the plugin. Disable the MCP JSON-RPC endpoint or the user-meta update tool, and restrict access to trusted administrators only. Enforce server-side capability checks so low-privilege users cannot modify role or capability metadata. Audit recent user role changes, admin accounts, and plugin activity for unauthorized modifications.

Risk context

The vulnerability is rated critical with a CVSS v3 score of 8.8. No EPSS score is provided. Urgency is high for WordPress sites with the plugin installed and any authenticated low-privilege users, because successful exploitation can lead to full site compromise.

Affected products

  • ByteCoreStack MCP Connector for AI Tools WordPress plugin
  • WordPress

Scores

Severity
critical
CVSS v2
9
CVSS v3
8.8
CVSS v4
—
EPSS
—

WordPress plugin privilege-escalation MCP JSON-RPC access-control user-meta

← All CVEs