PT-2026-63786 · WordPress · Mountdev Ai Mcp Connector

·

CVE-2026-15015

·

Published

2026-07-23

·

Updated

2026-07-23

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MountDev AI MCP Connector for WordPress versions prior to 1.6.2
Description An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Unauthenticated attackers can obtain an administrator-bound OAuth Bearer token by using a self-registered client. This grants full administrator-equivalent access to the plugin's MCP tool surface, as well as all exposed WordPress content, users, and options. The issue is exploited by combining the publicly accessible Dynamic Client Registration endpoint, which allows the registration of arbitrary OAuth clients with an attacker-controlled redirect uri, and the unprotected authorization endpoint to complete the OAuth flow without administrator interaction.
Recommendations Update MountDev AI MCP Connector for WordPress to version 1.6.2 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15015

Affected Products

Mountdev Ai Mcp Connector