CVE-2026-96525
Received Received - Intake

MCP Server Workflow Modification via Contributor Role

Vulnerability report for CVE-2026-96525, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: WPScan

Description

The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or sufficient capability check on its workflow create, update and delete REST routes, allowing users with the Contributor role to modify, delete and create site-wide workflow configuration, including workflows created by administrators.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpsecure mcp_server_for_wordpress to 1.8.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The MCP Server for WordPress plugin before version 1.8.2 has a vulnerability where it does not check if users have the proper permissions before allowing them to create, update, or delete workflows. This means users with the Contributor role can modify or delete workflows created by administrators, including site-wide configurations.

Detection Guidance

Check the installed version of the MCP Server for WordPress plugin. If it is below 1.8.2, the system is vulnerable. Use commands like 'wp plugin list' in WordPress or inspect the plugin directory for version details.

Impact Analysis

If you use the MCP Server for WordPress plugin before version 1.8.2, an attacker with the Contributor role could alter or delete important workflows, disrupting site operations or causing data loss. This could affect website functionality and integrity.

Compliance Impact

This vulnerability could lead to unauthorized changes in workflows, potentially violating data integrity and access control requirements in GDPR or HIPAA. Unauthorized modifications may result in non-compliance with these regulations.

Mitigation Strategies

Update the MCP Server for WordPress plugin to version 1.8.2 or later immediately. Remove or disable the plugin if an update is not possible. Review user roles to ensure Contributors do not have unnecessary permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96525. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart