Impact
The Royal MCP WordPress plugin contains an insufficient authorization flaw that is triggered after a user logs in via token authentication. Because the plugin does not verify the authenticated user’s capabilities for most of its MCP tools, low-privileged users such as Subscribers can read private content, enumerate all users and their roles, and create, modify, or delete content owned by other users. This results in data exposure and the ability to perform actions normally restricted to higher-privileged roles, effectively escalating privileges within the site.
Affected Systems
WordPress sites that have the Royal MCP plugin installed with a version earlier than 1.4.26. The vulnerability applies to the plugin’s MCP tools accessed after token authentication for any user, including those with low-privileged roles such as Subscriber.
Risk and Exploitability
The CVSS score of 8.1 indicates high impact on confidentiality, integrity, and availability. The EPSS score of less than 1% and absence from the CISA KEV catalog suggest a low current likelihood of exploitation. The flaw requires only an authenticated token, which can be obtained by any logged‑in user, making the attack path straightforward for an attacker who can create or gain access to a low-privileged account.
OpenCVE Enrichment