Vulnerability  ·  2026-07-25

MountDev AI MCP Connector for WordPress — Unauthenticated OAuth Client Registration Enables Full Admin Takeover

VulnerabilityHigh impactGlobalCVE-2026-15015
Wordfence disclosed CVE-2026-15015 (CVSS 9.8) describing a missing-authorization flaw in the MountDev AI MCP Connector plugin that lets unauthenticated attackers self-register OAuth clients and complete the authorization flow to mint admin-level Bearer tokens for the plugin's MCP tool surface.
This is a complete authentication bypass in an MCP connector exposed on any WordPress site, turning the LLM tool-integration surface into a direct path to full site takeover with zero authentication required — a severe blast radius given WordPress's massive install base and the growing adoption of MCP connectors for AI-powered site tooling.
Unauthenticated attacker combines the plugin's publicly accessible OAuth Dynamic Client Registration endpoint (allows registering arbitrary clients with attacker-controlled redirect_uri) with an unprotected authorization endpoint to complete a full OAuth flow without any administrator interaction, obtaining an administrator-bound OAuth Bearer token that grants full access to the plugin's MCP tool surface and all WordPress content, users, and options.
MountDev AI MCP Connector for WordPress ≤ 1.6.1
No official fix confirmed at time of disclosure (July 23, 2026) — restrict or disable the plugin's OAuth/MCP endpoints until a patch is released; monitor for unauthorized client registrations.
Wordfence/OffSeq CVE-2026-15015 report
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →