Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-96524

HIGH NVD
CVSS Score 8.8
Severity HIGH
Published Sep 26, 2026
Vendor unknown

Description

The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attackers to perform administrator-only actions, including creating a new administrator account, by tricking a logged-in administrator into visiting a crafted page.

References