Executive brief
The MountDev AI MCP Connector plugin for WordPress, which connects AI tools to website data, contains a critical security flaw that allows unauthorized individuals to gain full administrative control. By exploiting an unprotected registration process, an attacker can obtain a digital key that grants them the same permissions as a site administrator. This could lead to the theft of sensitive user data, modification of website content, or a complete takeover of the WordPress site.
Technical details
The MountDev AI MCP Connector for WordPress plugin (versions up to 1.6.1) suffers from a missing authorization check (CWE-862) in its OAuth implementation. The vulnerability stems from a publicly accessible Dynamic Client Registration endpoint that allows unauthenticated users to register arbitrary OAuth clients with attacker-controlled redirect URIs. When combined with an unprotected authorization endpoint, an attacker can complete the OAuth flow without administrator interaction to obtain an administrator-bound Bearer token. This grants full access to the plugin's Model Context Protocol (MCP) tool surface, including WordPress content, user data, and site options. A patch was introduced in version 1.6.2.
Affected products
- Cascadia Web Services MountDev AI MCP Connector for WordPress up to, and including, 1.6.1
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory
References
- https://plugins.trac.wordpress.org/browser/mountdev-ai-mcp-connector/tags/1.6.0/includes/class-oauth-controller.php
- https://plugins.trac.wordpress.org/browser/mountdev-ai-mcp-connector/tags/1.6.0/includes/class-oauth-controller.php
- https://plugins.trac.wordpress.org/browser/mountdev-ai-mcp-connector/tags/1.6.0/includes/class-oauth-controller.php
- https://plugins.trac.wordpress.org/browser/mountdev-ai-mcp-connector/tags/1.6.0/includes/class-oauth-controller.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3601448%40mountdev-ai-mcp-connector&new=3601448%40mountdev-ai-mcp-connector
- https://www.wordfence.com/threat-intel/vulnerabilities/id/ce8ec66f-5efc-4354-8871-8e35ab4e51fc?source=cve