VYPR

Royal MCP

by WordPress

CVEs (3)

  • CVE-2026-40775HigJun 15, 2026
    risk 0.47cvss 7.3epss 0.00

    Unauthenticated Broken Access Control in Royal MCP <= 1.4.2 versions.

  • CVE-2026-10750HigJul 1, 2026
    risk 0.00cvss 8.1epss 0.00

    The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP tools after token authentication, allowing authenticated users with a low-privileged role such as Subscriber to read private content, enumerate all users and their roles,…

  • CVE-2026-54842HigJun 25, 2026
    risk 0.00cvss 8.1epss 0.00

    Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal MCP: from n/a through 1.4.25.