HIGH
bytecorestack
CVE published 2026-10-01
CVE-2026-19807
The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3. This vulnerability allows authenticated attackers with Subscriber-level access and above to elevate their privileges to Administrator by exploiting the `wp_update_user_meta` MCP tool in `execute_tool`. The plugin's incomplete meta key blocklist leaves the ` [truncated]