Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Aeonrisk

#27866of 56,330
9.8Total CVSS
Vulnerabilities · 1
PT-2026-63786
9.8
2026-07-23
WordPress · Mountdev Ai Mcp Connector · CVE-2026-15015
**Name of the Vulnerable Software and Affected Versions** MountDev AI MCP Connector for WordPress versions prior to 1.6.2 **Description** An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Unauthenticated attackers can obtain an administrator-bound OAuth Bearer token by using a self-registered client. This grants full administrator-equivalent access to the plugin's MCP tool surface, as well as all exposed WordPress content, users, and options. The issue is exploited by combining the publicly accessible Dynamic Client Registration endpoint, which allows the registration of arbitrary OAuth clients with an attacker-controlled `redirect uri`, and the unprotected authorization endpoint to complete the OAuth flow without administrator interaction. **Recommendations** Update MountDev AI MCP Connector for WordPress to version 1.6.2 or later.