Description
Contributor Broken Access Control in IATO MCP <= 1.11.0 versions.
Published: 2026-10-06
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Broken Access Control leading to unauthorized privilege escalation
Action: Upgrade Plugin
AI Analysis

Impact

The IATO MCP plugin suffers from a broken access control flaw that permits users to perform actions beyond their intended permissions. This weakness can allow an attacker to read, modify, or delete sensitive content or configuration settings within the WordPress site, compromising data integrity and confidentiality.

Affected Systems

Any WordPress installation that has the IATO MCP plugin version 1.11.0 or earlier is affected. The vulnerability applies to the plugin regardless of site size or usage pattern, so every site that has not upgraded to a newer release is at risk.

Risk and Exploitability

The CVSS score of 6.5 classifies this as a medium severity vulnerability, and because the EPSS score is not available, the likelihood of exploitation is uncertain but not negligible. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is via the web interface of a WordPress site, inferred from the description of a broken access control flaw. It is inferred that attackers may exploit the flaw by leveraging authenticated accounts with limited privileges to gain higher level access or by using unauthenticated users to manipulate plugin functions, as the description indicates a broken access control without further detail.

Generated by OpenCVE AI on October 6, 2026 at 06:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the IATO MCP plugin to a version newer than 1.11.0.
  • If the upgrade is not immediately possible, remove or deactivate the plugin until a patch is available.
  • Revoke or tighten WordPress user roles so that non-administrative accounts cannot trigger plugin functions that may lead to privilege escalation.

Generated by OpenCVE AI on October 6, 2026 at 06:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 05:30:00 +0000

Type Values Removed Values Added
Description Contributor Broken Access Control in IATO MCP <= 1.11.0 versions.
Title WordPress IATO MCP plugin <= 1.11.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-06T05:14:46.484Z

Reserved: 2026-03-12T11:12:57.708Z

Link: CVE-2026-32582

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T06:17:00.660

Modified: 2026-10-06T06:17:00.660

Link: CVE-2026-32582

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T07:00:14Z

Weaknesses