VYPR

bcs-mcp-manager

by WordPress

CVEs (1)

  • CVE-2026-19807HigOct 1, 2026
    risk 0.50cvss 8.8epss —

    The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the `wp_update_user_meta` MCP tool in `execute_tool` gating writes solely with `current_user_can('edit_user',…