Impact
A flaw in the MountDev AI MCP Connector for WordPress allows an unauthenticated user to create a self‑registered OAuth client and then use the public authorization endpoint to obtain an administrator‑bound bearer token. The token grants full administrator‑equivalent access to the plugin’s MCP tool surface and to all exposed WordPress content, users, and options. By bypassing intended authorization checks, an attacker can manipulate or steal site data, modify settings, add or remove users, and perform any action that a legitimate administrator could execute.
Affected Systems
The vulnerability exists in the cascadiawebservices MountDev AI MCP Connector for WordPress plugin for all versions up to and including 1.6.1. Users running the plugin on any WordPress installation are affected, regardless of site size or configuration.
Risk and Exploitability
The CVSS score of 9.8 classifies the issue as critical. Although the EPSS score is less than 1 percent, indicating a low current exploitation probability, the potential damage is severe. The vulnerability is exploitable over the public network via the dynamic client registration and the unprotected authorization endpoints, with no requirement for administrator interaction or special credentials. This vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment