CVE-2026-96524
HIGH
NVD
CVSS Score
8.8
Severity
HIGH
Published
Sep 26, 2026
Vendor
unknown
Description
The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attackers to perform administrator-only actions, including creating a new administrator account, by tricking a logged-in administrator into visiting a crafted page.