What happened
WordFence and Patchstack documented a privilege-escalation flaw in the ByteCoreStack MCP Connector: the MCP tool that writes WordPress user meta validates only current_user_can('edit_user', $uid), which is misleadingly obtainable by non-administrators, allowing a low-privilege subscriber to modify user meta (including capability fields) and escalate to admin through the AI/MCP tool surface.
Why it matters
A WordPress-to-LLM bridge whose design intent is to let AI agents manage content dangerously exposes role escalation to the lowest trust tier. Small plugin, but it is a representative 'MCP tool granting admin via a single bad capability check' pattern for defenders auditing WordPress MCP connectors.
Attack vector
The wp_update_user_meta MCP tool in execute_tool gates writes solely with current_user_can('edit_user', $uid) — a capability check that WordPress grants to editors/contributors in several code paths — so a Subscriber+ authenticated user can cause the plugin's MCP server to escalate their role to administrator by returning arbitrary meta (CVSS 8.8 privilege escalation).
Affected systems
ByteCoreStack – MCP Connector for AI Tools WordPress plugin ≤ 1.2.3 (also catalogued as CVE-2026-103068 ≤ 1.2.2)
Mitigation
Update the plugin beyond 1.2.3 (patch via plugin update channel; advisory from Wordfence and Patchstack)