Vulnerability  ·  2026-10-07

WordPress MCP plugins broken access control pair — IATO MCP and WDS MCP Content Manager

VulnerabilityLow impactGlobalCVE-2026-32582
Two Patchstack-documented missing-authorization (CWE-862) flaws in niche WordPress MCP plugins: IATO MCP lets Contributor-level users invoke actions reserved for higher roles, and WDS MCP Content Manager (<=3.10.4) has a Contributor broken-access-control flaw. Both let low-privileged authenticated users reach MCP content-management capabilities intended for admins.
MCP plugins bridge WordPress content into AI agents; contributor-level access to MCP management capabilities lets a low-privilege user manipulate content/agent-facing tool configuration.
Authenticated low-privilege (Contributor) calls to plugin endpoints lacking capability checks.
IATO MCP <= 1.11.0 (CVE-2026-32582); WDS MCP Content Manager <= 3.10.4 (CVE-2026-39599)
Update plugin to fixed releases / restrict contributor access; contacts Patchstack for advisory details.
NVD CVE-2026-32582NVD CVE-2026-39599Patchstack advisoryPatchstack advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →