Junglewise Threat Intelligence

CVE-2026-54842: Royal Plugins Royal MCP missing authorization in access control

CVE-2026-54842 · Severity: high · CVSS 8.1 · Published 2026-06-25

Executive brief

Royal MCP, a WordPress plugin used for managing custom content and access levels, contains a security flaw that fails to properly verify user permissions. This allows logged-in users with low-level access, such as subscribers, to bypass security restrictions and perform administrative actions or access sensitive data. An exploit could lead to unauthorized changes to the website or the exposure of private information.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Royal Plugins Royal MCP plugin for WordPress through version 1.4.25. The flaw stems from insufficient permission checks on functions that manage access control security levels. An authenticated attacker with minimal privileges (e.g., a Subscriber) can exploit this to execute actions or access data intended for higher-privileged users. The vulnerability is exploitable over the network without user interaction. Users should update to version 1.4.26 or later to remediate the issue.

Affected products

  • Royal Plugins Royal MCP up to 1.4.25

Timeline

  • 2026-04-30: other: Reported by researcher dhamdham
  • 2026-06-18: advisory: Patchstack advisory published
  • 2026-06-25: disclosed: NVD publication date
  • 2026-06-25: patched: Patch confirmed available in version 1.4.26

References