CVE-2026-93529

6.5

Bilal Naseer · WSP MCP – AI Agents Connector

A broken access control vulnerability exists in the WSP MCP – AI Agents Connector plugin for WordPress, allowing authenticated contributors to perform unauthorized actions.

Executive summary

The WSP MCP – AI Agents Connector plugin for WordPress is vulnerable to a broken access control flaw that enables authenticated contributors to perform unauthorized actions.

Vulnerability

This vulnerability is classified as CWE-862, Missing Authorization. An authenticated attacker with contributor-level privileges can bypass intended security constraints to perform actions they are not authorized to execute.

Business impact

The ability for a lower-privileged user to perform unauthorized actions poses a significant risk to data integrity and site management. Although the CVSS score is 6.5 (Medium), the potential for unauthorized administrative or plugin-specific modifications can lead to service disruption or the unauthorized manipulation of AI agent configurations, potentially impacting business operations.

Remediation

Immediate Action: Update the WSP MCP – AI Agents Connector plugin to version 2.7.1 or the latest available version provided by the vendor.

Proactive Monitoring: Review WordPress access and audit logs for anomalous activity originating from contributor-level accounts, specifically focusing on unexpected configuration changes.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious requests targeting the plugin's endpoints until the patch is successfully applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the ease of access for authenticated contributors, it is imperative that administrators apply the update to version 2.7.1 immediately. Failure to patch this vulnerability may allow malicious actors to abuse the plugin's functionality, leading to unintended system changes. Prioritize this update within your standard patch management lifecycle.

History

  1. Analyst report written

Sources

Originally found and disclosed by Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program, per the CVE Program record.