Description
Unauthenticated Broken Access Control in Royal MCP <= 1.4.2 versions.
Published: 2026-06-15
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated Broken Access Control allows an attacker to execute actions normally restricted to authenticated users, potentially leading to unauthorized data access or modification. The weakness arises from improper authorization checks in the Royal MCP plugin, enabling privileged operations without credential verification. This flaw can compromise the confidentiality, integrity, and availability of site data.

Affected Systems

WordPress installations that include the Royal MCP plugin version 1.4.2 or earlier are affected. Royal Plugins, the provider of the plugin, is the only vendor identified. All sites running these versions remain vulnerable until the plugin is updated beyond 1.4.2.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity vulnerability. The EPSS score of < 1% suggests a low probability of exploitation at present, and the flaw is not listed in CISA KEV. The attack vector is inferred to be unauthenticated HTTP requests to privileged plugin endpoints, allowing attackers to perform restricted actions without needing valid credentials.

Generated by OpenCVE AI on June 16, 2026 at 23:22 UTC.

Remediation

Vendor Solution

Update the WordPress Royal MCP Plugin to the latest available version (at least 1.4.3).


OpenCVE Recommended Actions

  • Upgrade the Royal MCP plugin to version 1.4.3 or later to apply the vendor‑provided fix.
  • If an upgrade is not feasible, remove the Royal MCP plugin from the WordPress installation to eliminate the attack surface.
  • Review and tighten WordPress user role permissions, ensuring only authorized users can manage plugins and perform privileged actions.

Generated by OpenCVE AI on June 16, 2026 at 23:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 15 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Royal MCP <= 1.4.2 versions.
Title WordPress Royal MCP plugin <= 1.4.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-06-16T13:14:36.843Z

Reserved: 2026-04-15T09:20:36.793Z

Link: CVE-2026-40775

cve-icon Vulnrichment

Updated: 2026-06-16T13:07:40.952Z

cve-icon NVD

Status : Deferred

Published: 2026-06-15T21:16:50.227

Modified: 2026-06-15T21:24:32.790

Link: CVE-2026-40775

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-16T23:30:15Z

Weaknesses