CVE-2026-40775
Description
Unauthenticated broken access control in Royal MCP plugin <=1.4.2 allows unprivileged attackers to execute higher privileged actions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Unauthenticated broken access control in Royal MCP plugin <=1.4.2 allows unprivileged attackers to execute higher privileged actions.
Vulnerability
The Royal MCP plugin for WordPress versions up to and including 1.4.2 suffers from an unauthenticated broken access control vulnerability [1]. The issue is a missing authorization, authentication, or nonce token check in a function, allowing unprivileged users to execute higher privileged actions [1].
Exploitation
An attacker does not require authentication to exploit this vulnerability [1]. The vulnerability is expected to be used in mass-exploit campaigns, targeting thousands of websites regardless of size or popularity [1]. The exact sequence of steps is not detailed in the reference, but the lack of access control means an attacker can directly call the vulnerable function without any user interaction.
Impact
Successful exploitation allows an unauthenticated attacker to perform actions that should require higher privileges, potentially leading to full site compromise [1]. The CVSS score is 7.3 (High) [1].
Mitigation
The vulnerability is fixed in version 1.4.3 of the Royal MCP plugin [1]. Users are advised to update immediately. If unable to update, Patchstack provides a mitigation rule to block attacks until the patch is applied [1]. Auto-update can be enabled for vulnerable plugins [1].
AI Insight generated on Jun 15, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
0No linked articles in our index yet.