漏洞  ·  2026-10-04

Airano MCP Bridge WordPress plugin missing authorization — access to MCP bridge functions (CVE-2026-32585)

漏洞Medium 影响GlobalCVE-2026-32585
NVD published (2026-10-02) CVE-2026-32585, a Patchstack-documented missing-authorization (CWE-862) vulnerability in the Airano MCP Bridge WordPress plugin through 2.11.0, allowing exploitation of incorrectly configured access-control levels to reach MCP bridge functionality that should require higher privilege.
MCP bridge plugins give a WordPress site (and its AI agents) a tool surface; an authorization gap means lower-privileged WordPress users can drive MCP bridge functions they shouldn't, a direct agentic-tool authorization-bypass on the WordPress/MCP boundary.
Broken access control in the Airano MCP Bridge plugin lets a user lacking the required role/level invoke restricted MCP-bridge functions, exploiting incorrectly configured capability checks to reach functionality they should not be able to call
airano-mcp-bridge WordPress plugin from n/a through 2.11.0
No fixed version published as of the advisory; restrict/disable the Airano MCP Bridge plugin, audit which WordPress roles can reach its endpoints, and remove it from production if no patch is forthcoming (Patchstack advisory is the reference)
NVD: CVE-2026-32585Patchstack advisory
在实时动态中查看 浏览更多 AI 安全与治理相关发现 — 每日清晨更新。
打开动态 →