Impact
The MountDev AI MCP Connector for WordPress plugin contains a missing authorization flaw that allows attackers to invoke protected functions without proper authentication, potentially exposing sensitive data, modifying content, or executing administrative actions that should be restricted. This flaw aligns with CWE-862, which describes improper authorization weaknesses that enable unauthorized access to resources or functions.
Affected Systems
The vulnerability affects Cascadia Web Services' MountDev AI MCP Connector for WordPress plugin versions up to and including 1.6.5, with no earlier version verified as known.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate to high risk, although the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker can exploit the plugin’s administrative endpoints to bypass intended access controls, thus an authenticated or low‑privilege user can gain unauthorized access to protected functionality. The exploitation likelihood depends on the attacker’s ability to reach the WordPress site and the plugin’s exposed interfaces.
OpenCVE Enrichment