CVE-2026-93529: WordPress WSP MCP - AI Agents Connector plugin <= 2.7.0 - Broken Access Control vulnerability
Published Sep 23, 2026
·Updated
Contributor Broken Access Control in WSP MCP – AI Agents Connector <= 2.7.0 versions.
Affected Software
1 affected component
WordPress WSP MCP - AI Agents Connector<=2.7.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WSP MCP - AI Agents Connectorto a version that resolves this vulnerability.Fixed in 2.7.1
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
The vulnerability is associated with Contributor-level access. It does not indicate that an unauthenticated attacker can exploit it.
2
Does exploitation require user interaction or complex conditions?
The provided vector indicates network-based exploitation with low attack complexity and no user interaction required.
3
What is the expected security impact?
The severity vector indicates high integrity impact, with no indicated confidentiality or availability impact.