CVE-2026-97239: WordPress MCP Content Manager Lite plugin <= 1.1.0 - Broken Access Control vulnerability
Published Sep 30, 2026
·Updated
Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions.
Affected Software
1 affected component
WordPress MCP Content Manager Lite<=1.1.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress MCP Content Manager Lite Pluginto a version that resolves this vulnerability.Fixed in 1.2.0
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A user with Subscriber-level access can exploit the broken access control. The issue can be reached over the network, requires low privileges, and does not require user interaction.
2
What is the security impact?
Successful exploitation can result in unauthorized modification of content or other integrity-impacting actions. The provided data indicates no confidentiality or availability impact.
3
Which versions are affected?
MCP Content Manager Lite versions 1.1.0 and earlier are affected. The provided information does not identify a fixed version.