« Back to list

CVE-2026-19807

Status: ReceivedHigh (8.8)—

The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the `wp_update_user_meta` MCP tool in `execute_tool` gating writes solely with `current_user_can('edit_user', $uid)` — a check that WordPress core's `map_meta_cap` resolves to the `read` primitive when the target user ID matches the caller's own — while enforcing an incomplete meta key blocklist that covers only `user_pass`, `user_activation_key`, and `session_tokens`, leaving the `wp_capabilities` and `wp_user_level` meta keys entirely unprotected.

Read full descriptionShow less

This makes it possible for authenticated attackers with Subscriber-level access and above to elevate their privileges to Administrator by issuing a `wp_update_user_meta` call over the MCP JSON-RPC endpoint with `key=wp_capabilities` and an arbitrary role array such as `{'administrator': true}` targeting their own user ID, causing WordPress to load that account as an Administrator on the next request.

CVSS

Exploitation probability (EPSS)

FIRST hasn't scored this CVE yet (usual for very recent or rejected CVEs).

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-19807",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "security@wordfence.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@wordfence.com",
      "affectedData": [
        {
          "vendor": "bytecorestack",
          "product": "ByteCoreStack – MCP Connector for AI Tools",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "1.2.3"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-10-01T08:16:51.390",
  "references": [
    {
      "url": "https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.1.0/includes/MCP/Server.php#L2042",
      "source": "security@wordfence.com"
    },
    {
      "url": "https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.1.0/includes/MCP/Server.php#L2044",
      "source": "security@wordfence.com"
    },
    {
      "url": "https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.1.0/includes/MCP/Server.php#L2046",
      "source": "security@wordfence.com"
    },
    {
      "url": "https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.1.0/includes/MCP/Server.php#L332",
      "source": "security@wordfence.com"
    },
    {
      "url": "https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.1.0/includes/OAuth/Server.php#L122",
      "source": "security@wordfence.com"
    },
    {
      "url": "https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.2.0/includes/MCP/Server.php#L2042",
      "source": "security@wordfence.com"
    },
    {
      "url": "https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.2.0/includes/MCP/Server.php#L2044",
      "source": "security@wordfence.com"
    },
    {
      "url": "https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.2.0/includes/MCP/Server.php#L2046",
      "source": "security@wordfence.com"
    },
    {
      "url": "https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.2.0/includes/MCP/Server.php#L332",
      "source": "security@wordfence.com"
    },
    {
      "url": "https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.2.0/includes/OAuth/Server.php#L122",
      "source": "security@wordfence.com"
    },
    {
      "url": "https://plugins.trac.wordpress.org/changeset/3711908/bcs-mcp-manager/trunk/includes/MCP/Server.php",
      "source": "security@wordfence.com"
    },
    {
      "url": "https://plugins.trac.wordpress.org/changeset?reponame=&new=3711909%40bcs-mcp-manager%2Ftags%2F1.2.4&old=3711721%40bcs-mcp-manager%2Ftags%2F1.2.3",
      "source": "security@wordfence.com"
    },
    {
      "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ac09bf3e-49cf-4f11-92ba-d1fbf6f587d7?source=cve",
      "source": "security@wordfence.com"
    }
  ],
  "vulnStatus": "Received",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "security@wordfence.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the `wp_update_user_meta` MCP tool in `execute_tool` gating writes solely with `current_user_can('edit_user', $uid)` — a check that WordPress core's `map_meta_cap` resolves to the `read` primitive when the target user ID matches the caller's own — while enforcing an incomplete meta key blocklist that covers only `user_pass`, `user_activation_key`, and `session_tokens`, leaving the `wp_capabilities` and `wp_user_level` meta keys entirely unprotected. This makes it possible for authenticated attackers with Subscriber-level access and above to elevate their privileges to Administrator by issuing a `wp_update_user_meta` call over the MCP JSON-RPC endpoint with `key=wp_capabilities` and an arbitrary role array such as `{'administrator': true}` targeting their own user ID, causing WordPress to load that account as an Administrator on the next request."
    }
  ],
  "lastModified": "2026-10-01T08:16:51.390",
  "sourceIdentifier": "security@wordfence.com"
}