CVE-2026-96525: MCP Server for WordPress < 1.8.2 - Contributor+ Workflow Modification and Deletion via Missing Ownership Check
The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or sufficient capability check on its workflow create, update and delete REST routes, allowing users with the Contributor role to modify, delete and create site-wide workflow configuration, including workflows created by administrators.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MCP Server for WordPressto a version that resolves this vulnerability.Fixed in 1.8.2
Event History
Frequently Asked Questions
Who can exploit this issue?
A user with the WordPress Contributor role can exploit the affected workflow REST routes. They can act on site-wide workflow configuration, including workflows created by administrators.
What actions can an attacker perform?
An authenticated Contributor can create, modify, or delete workflows through the affected REST routes. The issue exists because those routes do not enforce workflow ownership or sufficient capability checks.
Which versions need remediation?
MCP Server for WordPress versions before 1.8.2 are affected. Updating to version 1.8.2 or later addresses the affected version range.