Impact
Unauthenticated Broken Access Control allows an attacker to execute actions normally restricted to authenticated users, potentially leading to unauthorized data access or modification. The weakness arises from improper authorization checks in the Royal MCP plugin, enabling privileged operations without credential verification. This flaw can compromise the confidentiality, integrity, and availability of site data.
Affected Systems
WordPress installations that include the Royal MCP plugin version 1.4.2 or earlier are affected. Royal Plugins, the provider of the plugin, is the only vendor identified. All sites running these versions remain vulnerable until the plugin is updated beyond 1.4.2.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity vulnerability. The EPSS score of < 1% suggests a low probability of exploitation at present, and the flaw is not listed in CISA KEV. The attack vector is inferred to be unauthenticated HTTP requests to privileged plugin endpoints, allowing attackers to perform restricted actions without needing valid credentials.
OpenCVE Enrichment