PT-2026-103715 · Bytecorestack · Bytecorestack – Mcp Connector For Ai Tools

·

CVE-2026-19807

·

Published

2026-10-01

·

Updated

2026-10-01

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the wp update user meta MCP tool in execute tool gating writes solely with current user can('edit user', $uid) — a check that WordPress core's map meta cap resolves to the read primitive when the target user ID matches the caller's own — while enforcing an incomplete meta key blocklist that covers only user pass, user activation key, and session tokens, leaving the wp capabilities and wp user level meta keys entirely unprotected. This makes it possible for authenticated attackers with Subscriber-level access and above to elevate their privileges to Administrator by issuing a wp update user meta call over the MCP JSON-RPC endpoint with key=wp capabilities and an arbitrary role array such as {'administrator': true} targeting their own user ID, causing WordPress to load that account as an Administrator on the next request.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19807

Affected Products

Bytecorestack – Mcp Connector For Ai Tools