rootpwn

critical · CVSS v3 9.8 · EPSS 0.001

CVE-2026-96524

The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for co…

Description

The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attackers to perform administrator-only actions, including creating a new administrator account, by tricking a logged-in administrator into visiting a crafted page.

Scores

Severity
critical
CVSS v2
6.5
CVSS v3
9.8
CVSS v4
—
EPSS
0.001

← All CVEs