Vulnerability  ·  2026-06-16

Royal MCP WordPress Plugin — Unauthenticated Broken Access Control (CVSS 7.3)

VulnerabilityHigh impactGlobalCVE-2026-40775
Royal MCP, a WordPress plugin that implements Model Context Protocol (MCP) server functionality enabling AI agents to interact with WordPress sites, contains an unauthenticated broken access control vulnerability in versions up to and including 1.4.2. Published June 15, 2026 (CVSS 7.3 HIGH). Remote attackers can reach protected MCP endpoints without authenticating.
MCP plugins expose structured tool interfaces specifically designed for AI agent consumption. An unauthenticated access control bypass on an MCP server allows external AI agents (or attackers posing as agents) to invoke any tool the plugin exposes — potentially reading, writing, or deleting WordPress content, accessing configured AI credentials, or using the compromised MCP endpoint as a pivot point to inject malicious context into legitimate AI agent workflows.
An unauthenticated remote attacker sends requests directly to Royal MCP's access-controlled endpoints, bypassing authentication checks due to improper authorization logic in versions ≤ 1.4.2. This grants access to MCP tool interfaces that AI agents use to interact with the WordPress site.
Royal MCP WordPress Plugin ≤ 1.4.2
Update Royal MCP to version 1.4.3 or later. Advisory: https://patchstack.com/database/wordpress/plugin/royal-mcp/vulnerability/wordpress-royal-mcp-plugin-1-4-2-broken-access-control-vulnerability
Sources
Patchstack Advisory — Royal MCP Broken Access Control CVE-2026-40775NVD CVE-2026-40775
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →