Vulnerability  ·  2026-10-03

ByteCoreStack MCP Connector for AI Tools (WordPress): subscriber privilege escalation to admin (CVE-2026-103068/19807)

VulnerabilityMedium impactGlobalCVE-2026-103068
NVD published two high CVSS-8.8 privilege-escalation CVEs for the ByteCoreStack MCP Connector for AI Tools WordPress plugin on 2026-10-01: the MCP tool's user-meta write gating is flawed, allowing Subscriber-to-admin escalation in the MCP-integrated WordPress context.
This is a WordPress AI/MCP plugin bringing an agent tool surface into WP; privilege escalation to admin gives full control over the site and any AI workflows attached to it — a narrow-blast-radius niche plugin CVE (Tier C).
The plugin's wp_update_user_meta MCP tool gates writes with current_user_can('edit_user', $uid) — a capability check vulnerable to bypass — letting a low-privilege Subscriber escalate privileges (CVSS 8.8).
ByteCoreStack – MCP Connector for AI Tools <= 1.2.2 (CVE-2026-103068), <= 1.2.3 (CVE-2026-19807)
Update the plugin beyond 1.2.3/patched release; audit for existing escalation while vulnerable.
NVD CVE-2026-103068NVD CVE-2026-19807
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →