CVE-2026-97242: WordPress WEBO MCP plugin <= 3.0.18 - Arbitrary File Deletion vulnerability
Published Sep 30, 2026
·Updated
Author Arbitrary File Deletion in WEBO MCP <= 3.0.18 versions.
Affected Software
1 affected component
WEBO WEBO MCP<=3.0.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WEBO MCP Pluginto a version that resolves this vulnerability.Fixed in 3.0.22
Event History
Sep 30, 2026
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Exploitation requires Author-level privileges. An unauthenticated attacker is not indicated by the available data.
2
What impact can successful exploitation have?
A successful attacker can delete arbitrary files. The listed impact is availability-focused, with no confidentiality or integrity impact specified.
3
Is user interaction required for exploitation?
No user interaction is required. The attack vector is network-based and the attack complexity is listed as low.
4
Which plugin versions are affected?
WEBO MCP versions 3.0.18 and earlier are identified as affected.