CVE-2026-96526
Received Received - Intake

MCP Server for WordPress Information Disclosure Vulnerability

Vulnerability report for CVE-2026-96526, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: WPScan

Description

The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one of its workflow REST routes, allowing users with the Contributor role to disclose the title and publication status of any post, page or custom post type, including other users' private, draft, pending and scheduled content.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The MCP Server for WordPress plugin before version 1.8.2 has a flaw where it does not check if users have permission to access certain data. This allows Contributors to view titles and publication status of any post, page, or custom post type, including private, draft, pending, or scheduled content from other users.

Detection Guidance

Check the installed version of the MCP Server for WordPress plugin. If it is below 1.8.2, the system is vulnerable. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files directly.

Impact Analysis

If you use this plugin, an attacker with a Contributor role could access sensitive information about posts they should not see. This includes unpublished or private content, potentially leaking confidential or draft material before it is ready for public release.

Compliance Impact

This vulnerability could lead to unauthorized access to private or sensitive data, which may violate GDPR's data protection principles or HIPAA's confidentiality requirements. Organizations using this plugin must ensure proper access controls to maintain compliance.

Mitigation Strategies

Update the MCP Server for WordPress plugin to version 1.8.2 or later immediately. If updating is not possible, consider disabling the plugin until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96526. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart