Junglewise Threat Intelligence

CVE-2026-15015: MountDev AI MCP Connector for WordPress authorization bypass

CVE-2026-15015 · Severity: critical · CVSS 9.8 · Published 2026-07-23

Executive brief

The MountDev AI MCP Connector plugin for WordPress, which connects AI tools to website data, contains a critical security flaw that allows unauthorized individuals to gain full administrative control. By exploiting an unprotected registration process, an attacker can obtain a digital key that grants them the same permissions as a site administrator. This could lead to the theft of sensitive user data, modification of website content, or a complete takeover of the WordPress site.

Technical details

The MountDev AI MCP Connector for WordPress plugin (versions up to 1.6.1) suffers from a missing authorization check (CWE-862) in its OAuth implementation. The vulnerability stems from a publicly accessible Dynamic Client Registration endpoint that allows unauthenticated users to register arbitrary OAuth clients with attacker-controlled redirect URIs. When combined with an unprotected authorization endpoint, an attacker can complete the OAuth flow without administrator interaction to obtain an administrator-bound Bearer token. This grants full access to the plugin's Model Context Protocol (MCP) tool surface, including WordPress content, user data, and site options. A patch was introduced in version 1.6.2.

Affected products

  • Cascadia Web Services MountDev AI MCP Connector for WordPress up to, and including, 1.6.1

Timeline

  • 2026-07-23: disclosed
  • 2026-07-23: advisory

References