HIGH
verygoodplugins
CVE published 2026-07-20
CVE-2026-46555
The WhatsApp MCP Server, enabling Claude to read and send WhatsApp messages, has vulnerabilities allowing unauthorized message sending and file reading due to lack of authentication and Host header validation. Users should be aware of these issues and address them to prevent unauthorized access and data exfiltration. The CVE record was published on 2026-07-20T17:17:09.820Z and has not been modified since [truncated]