CVE-2026-103068: WordPress ByteCoreStack – MCP Connector for AI Tools plugin <= 1.2.2 - Privilege Escalation vulnerability
Published Oct 1, 2026
·Updated
Subscriber Privilege Escalation in ByteCoreStack – MCP Connector for AI Tools <= 1.2.2 versions.
Affected Software
1 affected component
WordPress ByteCoreStack – MCP Connector for AI Tools<=1.2.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress ByteCoreStack – MCP Connector for AI Toolsto a version that resolves this vulnerability.Fixed in 1.2.4
Event History
Oct 1, 2026
CVE Published
via MITRE·02:34 PM
Data Sourced
via MITRE·02:34 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations should be treated as affected?
Installations running version 1.2.2 or earlier of the ByteCoreStack MCP Connector for AI Tools WordPress plugin should be treated as affected.
2
What access does an attacker need to exploit this issue?
The CVSS vector indicates network access is sufficient and the attacker needs low-level privileges. No user interaction is required.
3
What could a successful exploit allow?
The issue is rated high severity with high impact to confidentiality, integrity, and availability. It could allow a subscriber-level user to escalate privileges.