Description
The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP tools after token authentication, allowing authenticated users with a low-privileged role such as Subscriber to read private content, enumerate all users and their roles, and create, modify, or delete content owned by other users.
Published: 2026-07-01
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Royal MCP WordPress plugin contains an insufficient authorization flaw that is triggered after a user logs in via token authentication. Because the plugin does not verify the authenticated user’s capabilities for most of its MCP tools, low-privileged users such as Subscribers can read private content, enumerate all users and their roles, and create, modify, or delete content owned by other users. This results in data exposure and the ability to perform actions normally restricted to higher-privileged roles, effectively escalating privileges within the site.

Affected Systems

WordPress sites that have the Royal MCP plugin installed with a version earlier than 1.4.26. The vulnerability applies to the plugin’s MCP tools accessed after token authentication for any user, including those with low-privileged roles such as Subscriber.

Risk and Exploitability

The CVSS score of 8.1 indicates high impact on confidentiality, integrity, and availability. The EPSS score of less than 1% and absence from the CISA KEV catalog suggest a low current likelihood of exploitation. The flaw requires only an authenticated token, which can be obtained by any logged‑in user, making the attack path straightforward for an attacker who can create or gain access to a low-privileged account.

Generated by OpenCVE AI on August 5, 2026 at 03:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Royal MCP plugin to version 1.4.26 or newer to restore proper capability checks for all MCP tools.
  • If an update cannot be applied immediately, limit the use of the MCP tools to Administrator or higher roles, using a role‑restriction plugin or similar access control mechanism.
  • Alternatively, disable token authentication for the Royal MCP plugin or block token‑based requests to reduce the attack surface until a patch can be applied.
  • Regularly monitor for new vulnerability advisories and apply available updates as soon as possible.

Generated by OpenCVE AI on August 5, 2026 at 03:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-250
CWE-284

Tue, 04 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Wed, 29 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Mon, 27 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 16 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 14 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 13 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 12 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 10 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 09 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 08 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 08 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 07 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 06 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 06 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 05 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 04 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 04 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 04 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 03 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 03 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 02 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 02 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 02 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 01 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 01 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 01 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP tools after token authentication, allowing authenticated users with a low-privileged role such as Subscriber to read private content, enumerate all users and their roles, and create, modify, or delete content owned by other users.
Title Royal MCP < 1.4.26 - Subscriber+ Insufficient Authorization in MCP Tools
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-01T10:20:41.864Z

Reserved: 2026-06-03T13:54:53.609Z

Link: CVE-2026-10750

cve-icon Vulnrichment

Updated: 2026-07-01T10:20:38.248Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T03:30:06Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges

  • CWE-284

    Improper Access Control