Impact
The Royal MCP WordPress plugin before version 1.4.26 contains an insufficient authorization flaw that is triggered after a user logs to verify that the authenticated user has the appropriate capabilities for most of its MCP tools. As a result, even low‑privileged users such as Subscribers can read private content, enumerate all users and their roles, and create, modify, or delete content owned by other users. The impact is dual: confidential information is exposed and the attacker can perform actions normally restricted to higher‑privileged roles, effectively achieving privilege escalation within the site WordPress installation that has the Royal MCP plugin that is older than version 1.4.26 is affected. Sites still running a vulnerable instance therefore remain at risk of these unauthorized actions until the plugin is upgraded or mitigated.
Affected Systems
WordPress sites running the Royal MCP plugin on any installation where the plugin version is less than 1.4.26; the vulnerability applies to the plugin’s MCP tools accessed after token authentication for users with any role, including Subscribers.
Risk and Exploitability
The EPSS score is less than 1%, and the vulnerability is not listed in CISA KEV, indicating a low current likelihood of exploitation. The flaw requires only that the attacker has a valid authenticated token, which is typically a low‑privileged role such as a Subscriber. The CVSS score of 8.1 reflects the high potential impact on confidentiality, integrity, and availability. Attackers would exploit the missing capability checks to read, modify, or delete content and to gather sensitive information about site users and roles.
OpenCVE Enrichment