Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-19807 Details

Description

The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the `wp_update_user_meta` MCP tool in `execute_tool` gating writes solely with `current_user_can('edit_user', $uid)` — a check that WordPress core's `map_meta_cap` resolves to the `read` primitive when the target user ID matches the caller's own — while enforcing an incomplete meta key blocklist that covers only `user_pass`, `user_activation_key`, and `session_tokens`, leaving the `wp_capabilities` and `wp_user_level` meta keys entirely unprotected. This makes it possible for authenticated attackers with Subscriber-level access and above to elevate their privileges to Administrator by issuing a `wp_update_user_meta` call over the MCP JSON-RPC endpoint with `key=wp_capabilities` and an arbitrary role array such as `{'administrator': true}` targeting their own user ID, causing WordPress to load that account as an Administrator on the next request.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.1.0/includes/MCP/Server.php#L2042 [email protected]
https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.1.0/includes/MCP/Server.php#L2044 [email protected]
https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.1.0/includes/MCP/Server.php#L2046 [email protected]
https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.1.0/includes/MCP/Server.php#L332 [email protected]
https://plugins.trac.wordpress.org/browser/bcs-mcp-manager/tags/1.1.0/includes/OAuth/Server.php#L122 [email protected]

see all 13 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-269Improper Privilege Management[email protected]

Affected Products

No affected product data is available for this CVE.

Change History

1 change record found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-19807
NVD Published Date:
Oct 1, 2026
NVD Last Modified:
Oct 1, 2026
Source:
[email protected]
CVE-2026-19807 Details - Not Deferred