Impact
The vulnerability is a broken access control flaw in the WordPress WSP MCP – AI Agents Connector plugin. It allows an attacker to manipulate and perform actions that should be restricted to privileged users, potentially compromising the integrity and confidentiality of data managed by the plugin.
Affected Systems
The affected product is Bilal Naseer’s WSP MCP – AI Agents Connector plugin for WordPress. Versions up to and including 2.7.0 contain the flaw, while 2.7.1 and later are considered safe.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the nature of the weakness, the likely attack vector is a remote web-based exploit performed through the plugin’s administrative interface, and the attacker may need authenticated access to take advantage of the broken control.
OpenCVE Enrichment