PatchSiren cyber security CVE debrief
CVE-2026-19807 bytecorestack CVE debrief
The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3. This vulnerability allows authenticated attackers with Subscriber-level access and above to elevate their privileges to Administrator by exploiting the `wp_update_user_meta` MCP tool in `execute_tool`. The plugin's incomplete meta key blocklist leaves the `wp_capabilities` and `wp_user_level` meta keys unprotected, enabling attackers to modify these keys via the MCP JSON-RPC endpoint.
- Vendor
- bytecorestack
- Product
- ByteCoreStack – MCP Connector for AI Tools
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-01
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-01
- Advisory updated
- 2026-10-03
Who should care
WordPress administrators, security teams, and users of the ByteCoreStack – MCP Connector for AI Tools plugin should be aware of this vulnerability and take immediate action to prevent potential privilege escalation attacks.
Why it matters
CVE-2026-19807 is a Privilege Escalation vulnerability in the ByteCoreStack – MCP Connector for AI Tools plugin for WordPress. Authenticated attackers with Subscriber-level access can exploit this vulnerability to elevate their privileges to Administrator, potentially leading to unauthorized access and control. Defenders should verify plugin presence and version, update to a patched version if available, and monitor for suspicious activity.
- Verification of plugin presence and version is required to determine exposure.
- Authenticated attackers with Subscriber-level access can potentially escalate privileges to Administrator.
- Modifying `wp_capabilities` and `wp_user_level` meta keys can lead to unauthorized access and control.
- Immediate patching or mitigation is necessary to prevent exploitation.
Technical summary
The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation due to inadequate access controls in the `wp_update_user_meta` MCP tool. Specifically, the plugin uses `current_user_can('edit_user', $uid)` which resolves to the `read` primitive when the target user ID matches the caller's own. Additionally, the plugin's meta key blocklist is incomplete, leaving critical meta keys like `wp_capabilities` and `wp_user_level` unprotected. This allows authenticated attackers with Subscriber-level access and above to elevate their privileges to Administrator by modifying these meta keys via the MCP JSON-RPC endpoint.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their WordPress installations, especially if the ByteCoreStack – MCP Connector for AI Tools plugin is used. Immediate action is required to prevent potential privilege escalation attacks.
Recommended defensive actions
- Verify the presence of the ByteCoreStack – MCP Connector for AI Tools plugin in your WordPress installation.
- Check if the plugin version is 1.2.3 or earlier.
- Update the plugin to a patched version if available.
- Monitor for suspicious `wp_update_user_meta` calls via the MCP JSON-RPC endpoint.
- Restrict access to the MCP JSON-RPC endpoint to authorized users only.
Evidence notes
The vulnerability is confirmed by the CVE Program and NVD records. Details are provided by Wordfence security researchers. However, the exact scope of affected deployments and potential exploitation attempts remain unknown.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19807 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19807
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19807 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19807
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.1.0/includes/MCP/Server.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.1.0/includes/OAuth/Server.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.2.0/includes/MCP/Server.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.2.0/includes/OAuth/Server.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/changeset/3711908/bcs-mcp-manager/trunk/includes/MCP/Server.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.