See how bytecorestack compares to other vendors in security performance
The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the wpupdateusermeta MCP tool in executetool gating writes solely with currentusercan('edituser', $uid) — a check that WordPress core's mapmetacap resolves to the read primitive when the target user ID matches the caller's own — while enforcing an incomplete meta key blocklist that covers only userpass, useractivationkey, and sessiontokens, leaving the wpcapabilities and wpuserlevel meta keys entirely unprotected. This makes it possible for authenticated attackers with Subscriber-level access and above to elevate their privileges to Administrator by issuing a wpupdateusermeta call over the MCP JSON-RPC endpoint with key=wpcapabilities and an arbitrary role array such as {'administrator': true} targeting their own user ID, causing WordPress to load that account as an Administrator on the next request.