CVE-2026-19807 Privilege Escalation in ByteCoreStack MCP Connector for AI Tools
The ByteCoreStack MCP Connector for AI Tools plugin for WordPress is vulnerable to privilege escalation via insufficient meta key validation, allowing Subscriber-level users to escalate to Administrator.
CVE search metadata
CVE search record: CVE-2026-19807. Severity: high. CVSS: 8.8. KEV: no. Product: MCP Connector for AI Tools (<= 1.2.3). Brief: CVE-2026-19807 Privilege Escalation in ByteCoreStack MCP Connector for AI Tools. Brief link: https://feed.craftedsignal.io/briefs/2026-10-bytecorestack-mcp-privesc/
The ByteCoreStack - MCP Connector for AI Tools plugin for WordPress, in all versions up to and including 1.2.3, contains a critical privilege escalation vulnerability. The flaw exists within the execute_tool function when handling the wp_update_user_meta MCP tool. The implementation relies on current_user_can('edit_user', $uid) for authorization, which, when the target user ID matches the caller ID, defaults to the 'read' primitive. Furthermore, the plugin utilizes an insufficient blocklist for user meta keys, explicitly blocking user_pass, user_activation_key, and session_tokens, but failing to protect wp_capabilities and wp_user_level. Authenticated users with Subscriber access can exploit this to overwrite their own meta keys, granting themselves Administrator-level privileges. This issue poses a severe risk to WordPress instances utilizing this AI-connector plugin, as it facilitates full site compromise through unauthorized administrative access.
Impact
Successful exploitation of CVE-2026-19807 enables an authenticated Subscriber-level user to gain full Administrator control over the affected WordPress instance. This results in the potential for complete site takeover, including code execution via plugin installation, data exfiltration, and full database access. Given the nature of WordPress privileges, this vulnerability is critical for all installations currently using version 1.2.3 or earlier of the affected plugin.
Recommendation
- Immediately audit current ByteCoreStack MCP Connector plugin versions and restrict usage of the plugin until a vendor patch addressing the improper meta key validation is applied.
- Monitor web server logs for suspicious requests to MCP JSON-RPC endpoints that include parameters containing 'wp_capabilities' or 'wp_user_level' meta keys.
- Enable security audit logging for user metadata updates to identify unauthorized elevation attempts.
Immediate actions
Inventory all WordPress instances running ByteCoreStack MCP Connector
Mitigations
Disable ByteCoreStack MCP Connector plugin until a vendor security update is verified
CVE-2026-19807
Detection coverage 1
Detects CVE-2026-19807 Exploitation - Unauthorized User Meta Update
highDetects exploitation attempts targeting CVE-2026-19807 by looking for JSON-RPC requests containing restricted user meta keys like wp_capabilities or wp_user_level.
Detection queries are available on the platform. Get full rules →