CVE-2026-19807: ByteCoreStack <= 1.2.3 - Authenticated (Subscriber+) Privilege Escalation via wp_update_user_meta MCP Tool

Published Oct 1, 2026
·
Updated

The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the wpupdateusermeta MCP tool in executetool gating writes solely with currentusercan('edituser', $uid) — a check that WordPress core's mapmetacap resolves to the read primitive when the target user ID matches the caller's own — while enforcing an incomplete meta key blocklist that covers only userpass, useractivationkey, and sessiontokens, leaving the wpcapabilities and wpuserlevel meta keys entirely unprotected. This makes it possible for authenticated attackers with Subscriber-level access and above to elevate their privileges to Administrator by issuing a wpupdateusermeta call over the MCP JSON-RPC endpoint with key=wpcapabilities and an arbitrary role array such as {'administrator': true} targeting their own user ID, causing WordPress to load that account as an Administrator on the next request.

Affected Software

1 affected component
ByteCoreStack MCP Connector for AI Tools<=1.2.3

Event History

Oct 1, 2026
CVE Published
via MITRE·07:40 AM
Data Sourced
via MITRE·07:40 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated WordPress user with Subscriber-level access or higher can exploit it. The attacker only needs to target their own user ID through the MCP JSON-RPC endpoint.

2

Does exploitation require administrator interaction or a special configuration?

No user interaction is required. The vulnerable MCP tool permits the privilege-changing user-meta update because a user can satisfy the authorization check when modifying their own account.

3

How can I tell whether an account may already have been elevated?

Review WordPress user metadata for unexpected wp_capabilities or wp_user_level values, particularly Subscriber or other low-privilege accounts carrying an administrator role. Also review access to the MCP JSON-RPC endpoint for wp_update_user_meta calls that update wp_capabilities.

4

What can be done if updating is not immediately possible?

Restrict access to the MCP JSON-RPC endpoint so low-privilege authenticated users cannot invoke the wp_update_user_meta tool. Monitor for and remove unauthorized administrator role assignments by checking wp_capabilities and wp_user_level metadata.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203