Vulnerability  ·  2026-10-01

WordPress MCP plugins: WEBO MCP arbitrary file deletion and MCP Content Manager Lite broken access control

VulnerabilityMedium impactGlobalCVE-2026-97242
Two Patchstack-documented WordPress MCP-plugin authorization flaws published 2026-09-30 (CVSS 6.8 and 6.5). Niche plugins, low blast radius, no known exploits.
WordPress MCP plugins expose site content/tools to AI agents; broken authorization on the MCP control surface lets low-privilege or agent-led calls reach destructive or privileged actions.
WEBO MCP allows an author-level account to delete arbitrary files; MCP Content Manager Lite lets subscriber-level users invoke privileged content-management actions over the MCP surface.
WordPress WEBO MCP plugin <= 3.0.18; MCP Content Manager Lite <= 1.1.0
Update WEBO MCP beyond 3.0.18 and MCP Content Manager Lite beyond 1.1.0.
Patchstack WEBO MCP advisoryNVD CVE-2026-97242NVD CVE-2026-97239
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →