What happened
Two Patchstack-documented WordPress MCP-plugin authorization flaws published 2026-09-30 (CVSS 6.8 and 6.5). Niche plugins, low blast radius, no known exploits.
Why it matters
WordPress MCP plugins expose site content/tools to AI agents; broken authorization on the MCP control surface lets low-privilege or agent-led calls reach destructive or privileged actions.
Attack vector
WEBO MCP allows an author-level account to delete arbitrary files; MCP Content Manager Lite lets subscriber-level users invoke privileged content-management actions over the MCP surface.
Affected systems
WordPress WEBO MCP plugin <= 3.0.18; MCP Content Manager Lite <= 1.1.0
Mitigation
Update WEBO MCP beyond 3.0.18 and MCP Content Manager Lite beyond 1.1.0.