Vulnerability  ·  2026-09-27

MCP Server for WordPress: nonce-check bypass lets unauthenticated attackers perform admin actions; broken access control on workflow routes (CVE-2026-96524/96525/96526)

VulnerabilityHigh impactGlobalCVE-2026-96524
NVD published the three-CVE cluster on 2026-09-26 for the MCP Server for WordPress plugin before 1.8.2, fixing nonce verification and workflow-route authorization issues. Attackers do not need to exploit the model itself — classic OWASP Web flaws (CSRF, missing authz) in the MCP bridge.
This is an AI-relevant MCP bridge whose compromise means an attacker gets administrator control of a WordPress site (via the AI-agent plumbing, not the LLM). Any site exposing the MCP server is a takeover vector; Combined with 96525/96526, even low-privileged contributors can corrupt the agents' workflow configuration (a form of agent tool poisoning at the platform layer). Upgrade to 1.8.2+ immediately.
CVE-2026-96524: REST API nonce is not verified for cookie-authenticated requests when an attacker-influenced condition holds — a logged-in admin visiting a crafted page can be coerced into creating a new administrator account (CWE-352). CVE-2026-96525/96526: workflow create/update/delete REST routes lack ownership/capability checks, letting Contributor users alter site-wide AI workflow configuration and enumerate private content.
Upgrade to MCP Server for WordPress 1.8.2 or later (fixes nonce verification and workflow-route authorization).
NVD - CVE-2026-96524WPScan advisory for CVE-2026-96524mcpplaygroundonline.com MCP server vulnerability analysis
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →