CVE-2026-85306: WordPress MountDev AI MCP Connector for WordPress plugin <= 1.6.5 - Broken Access Control vulnerability
Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects MountDev AI MCP Connector for WordPress: from n/a through 1.6.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress MountDev AI MCP Connector for WordPress pluginto a version that resolves this vulnerability.Fixed in 1.6.6
Event History
Frequently Asked Questions
Who could exploit this issue?
The CVSS vector indicates that exploitation is network-accessible, requires low privileges, and does not require user interaction. An attacker would need an authenticated account with limited privileges.
What is the security impact?
The reported impact is high integrity impact, with no reported confidentiality or availability impact. Successful exploitation could allow unauthorized modification through incorrectly configured access control.
Which versions are affected?
MountDev AI MCP Connector for WordPress versions through 1.6.5 are affected. The provided data does not identify a fixed version.