PT-2026-52419 · Royal Plugin+1 · Royal Mcp

·

CVE-2026-54842

·

Published

2026-06-18

·

Updated

2026-06-25

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Royal MCP versions prior to 1.4.26
Description Royal MCP for WordPress contains a missing authorization flaw resulting from an incorrectly configured access control security level. The issue stems from a missing capability check within a function, allowing authenticated users with subscriber-level access or higher to perform unauthorized actions.
Recommendations Update Royal MCP to version 1.4.26 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54842

Affected Products

Royal Mcp