Executive brief
The MCP Server for WordPress plugin before version 1.8.2 fails to properly validate user permissions on workflow management features, allowing contributors to create, modify, and delete workflows intended only for administrators. This lets low-privileged users alter site-wide automation configurations and disable workflows set up by site administrators.
Technical details
The plugin's workflow create, update, and delete REST API endpoints lack proper ownership and capability checks, allowing users with the Contributor role to modify workflows across the site. Exploitation requires network access and WordPress contributor-level authentication; the vulnerability affects workflow management REST routes that should be restricted to higher privilege levels. No CVSS score is publicly available, though WPScan rates this as CVSS 2.7 (low); the plugin was patched in version 1.8.2.
Affected products
- Eliot Costa MCP Server for WordPress before 1.8.2
Timeline
- 2026-09-24: disclosed
- 2026-09-26: patched: Version 1.8.2 released