CVE WATCH / VULNERABILITY DETAIL

CVE-2026-19807

HIGHCVSS 8.8NVD feed

Published 1 October 2026 · tracked since 1 October 2026

Description

The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the `wp_update_user_meta` MCP tool in `execute_tool` gating writes solely with `current_user_can('edit_user', $uid)` — a check that Wor

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-19807 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-19807

HIGHCVSS 8.8NVD feed

Published 1 October 2026 · tracked since 1 October 2026

Description

The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the `wp_update_user_meta` MCP tool in `execute_tool` gating writes solely with `current_user_can('edit_user', $uid)` — a check that Wor

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]