What happened
NVD published two high CVSS-8.8 privilege-escalation CVEs for the ByteCoreStack MCP Connector for AI Tools WordPress plugin on 2026-10-01: the MCP tool's user-meta write gating is flawed, allowing Subscriber-to-admin escalation in the MCP-integrated WordPress context.
Why it matters
This is a WordPress AI/MCP plugin bringing an agent tool surface into WP; privilege escalation to admin gives full control over the site and any AI workflows attached to it — a narrow-blast-radius niche plugin CVE (Tier C).
Attack vector
The plugin's wp_update_user_meta MCP tool gates writes with current_user_can('edit_user', $uid) — a capability check vulnerable to bypass — letting a low-privilege Subscriber escalate privileges (CVSS 8.8).
Affected systems
ByteCoreStack – MCP Connector for AI Tools <= 1.2.2 (CVE-2026-103068), <= 1.2.3 (CVE-2026-19807)
Mitigation
Update the plugin beyond 1.2.3/patched release; audit for existing escalation while vulnerable.