VYPR
High severity7.3NVD Advisory· Published Jun 15, 2026· Updated Jun 15, 2026

CVE-2026-40775

CVE-2026-40775

Description

Unauthenticated broken access control in Royal MCP plugin <=1.4.2 allows unprivileged attackers to execute higher privileged actions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unauthenticated broken access control in Royal MCP plugin <=1.4.2 allows unprivileged attackers to execute higher privileged actions.

Vulnerability

The Royal MCP plugin for WordPress versions up to and including 1.4.2 suffers from an unauthenticated broken access control vulnerability [1]. The issue is a missing authorization, authentication, or nonce token check in a function, allowing unprivileged users to execute higher privileged actions [1].

Exploitation

An attacker does not require authentication to exploit this vulnerability [1]. The vulnerability is expected to be used in mass-exploit campaigns, targeting thousands of websites regardless of size or popularity [1]. The exact sequence of steps is not detailed in the reference, but the lack of access control means an attacker can directly call the vulnerable function without any user interaction.

Impact

Successful exploitation allows an unauthenticated attacker to perform actions that should require higher privileges, potentially leading to full site compromise [1]. The CVSS score is 7.3 (High) [1].

Mitigation

The vulnerability is fixed in version 1.4.3 of the Royal MCP plugin [1]. Users are advised to update immediately. If unable to update, Patchstack provides a mitigation rule to block attacks until the patch is applied [1]. Auto-update can be enabled for vulnerable plugins [1].

AI Insight generated on Jun 15, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.