CVE-2026-32582: WordPress IATO MCP plugin <= 1.11.0 - Broken Access Control vulnerability
Published Oct 6, 2026
·Updated
Contributor Broken Access Control in IATO MCP <= 1.11.0 versions.
Affected Software
1 affected component
WordPress IATO MCP plugin<=1.11.0
Event History
Oct 6, 2026
CVE Published
via MITRE·05:14 AM
Data Sourced
via MITRE·05:14 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Exploitation requires low-level privileges, consistent with a Contributor-level access scenario. The attack can be performed over the network and does not require user interaction.
2
What is the likely security impact?
The reported impact is high on integrity, meaning an attacker may be able to make unauthorized changes. No confidentiality or availability impact is reported.
3
Which plugin versions are affected?
IATO MCP versions up to and including 1.11.0 are identified as affected.