Junglewise Threat Intelligence

CVE-2026-85306: Cascadia Web Services MountDev AI MCP Connector broken access control

CVE-2026-85306 · Severity: medium · CVSS 6.5 · Published 2026-09-03

Executive brief

The MountDev AI MCP Connector is a WordPress plugin that integrates AI capabilities into WordPress sites. A broken access control vulnerability allows users with lower privilege levels (such as contributors) to access pages and perform actions they should not be authorized to, potentially exposing sensitive data or enabling unauthorized modifications to site content.

Technical details

The vulnerability is a broken access control flaw (OWASP A1) in the MountDev AI MCP Connector for WordPress plugin versions up to 1.6.5. The root cause is incorrectly configured access control security levels that fail to properly enforce authorization checks. An authenticated user with contributor privileges can exploit this vulnerability to access pages or perform actions beyond their assigned permissions. The vulnerability requires authentication but only at the contributor level, making it relatively easy to exploit. A patch is available in version 1.6.6 and later.

Affected products

  • Cascadia Web Services MountDev AI MCP Connector through 1.6.5

Timeline

  • 2026-08-28: disclosed: Reported by Ananda Dhakal (Patchstack)
  • 2026-09-03: advisory: Published by Patchstack and NVD
  • 2026: patched: Fixed in version 1.6.6

References