Royal MCP
by WordPress
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-40775 | Hig | 0.47 | 7.3 | 0.00 | Jun 15, 2026 | Unauthenticated Broken Access Control in Royal MCP <= 1.4.2 versions. | ||
| CVE-2026-10750 | Hig | 0.00 | 8.1 | 0.00 | Jul 1, 2026 | The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP tools after token authentication, allowing authenticated users with a low-privileged role such as Subscriber to read private content, enumerate all users and their roles,… | ||
| CVE-2026-54842 | Hig | 0.00 | 8.1 | 0.00 | Jun 25, 2026 | Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal MCP: from n/a through 1.4.25. |
- risk 0.47cvss 7.3epss 0.00
Unauthenticated Broken Access Control in Royal MCP <= 1.4.2 versions.
- risk 0.00cvss 8.1epss 0.00
The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP tools after token authentication, allowing authenticated users with a low-privileged role such as Subscriber to read private content, enumerate all users and their roles,…
- risk 0.00cvss 8.1epss 0.00
Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal MCP: from n/a through 1.4.25.