Junglewise Threat Intelligence

CVE-2026-40775: Royal MCP broken access control in WordPress plugin

CVE-2026-40775 · Severity: high · CVSS 7.3 · Published 2026-06-15

Executive brief

Royal MCP, a WordPress plugin, contains a security flaw that allows unauthorized individuals to perform actions they should not have access to. An attacker could exploit this to modify site settings or access restricted data without needing a password. This could lead to unauthorized changes to the website or the exposure of sensitive information.

Technical details

The Royal MCP plugin for WordPress suffers from a broken access control vulnerability (CWE-862) due to missing authorization checks in its functional logic. An unauthenticated remote attacker can exploit this flaw by sending crafted network requests to the affected site, bypassing intended restrictions. This allows the attacker to execute actions typically reserved for higher-privileged users, potentially impacting the confidentiality, integrity, and availability of the site. The vulnerability is resolved in version 1.4.3.

Affected products

  • Royal MCP Royal MCP <= 1.4.2

Timeline

  • 2026-03-10: other: Reported by Alexis Lafontaine
  • 2026-04-21: advisory: Initial advisory published by Patchstack
  • 2026-06-15: disclosed: NVD publication date

References