WordPress Plugin Vulnerabilities

MCP Server for WordPress < 1.8.2 - Administrator Account Creation via CSRF

Description

The plugin does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attackers to perform administrator-only actions, including creating a new administrator account, by tricking a logged-in administrator into visiting a crafted page.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Raphael P. Cigana
Submitter
Raphael P. Cigana
Verified
Yes

Timeline

Publicly Published
2026-09-24 (about 2 days ago)
Added
2026-09-24 (about 1 day ago)
Last Updated
2026-09-25 (about 8 hours ago)

Other