PatchSiren

bytecorestack CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH bytecorestack CVE published 2026-10-01

CVE-2026-19807

The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3. This vulnerability allows authenticated attackers with Subscriber-level access and above to elevate their privileges to Administrator by exploiting the `wp_update_user_meta` MCP tool in `execute_tool`. The plugin's incomplete meta key blocklist leaves the ` [truncated]