Skip to content
Threat Feed
high advisory

CVE-2026-19807 Privilege Escalation in ByteCoreStack MCP Connector for AI Tools

The ByteCoreStack MCP Connector for AI Tools plugin for WordPress is vulnerable to privilege escalation via insufficient meta key validation, allowing Subscriber-level users to escalate to Administrator.

CVE search metadata

CVE search record: CVE-2026-19807. Severity: high. CVSS: 8.8. KEV: no. Product: MCP Connector for AI Tools (<= 1.2.3). Brief: CVE-2026-19807 Privilege Escalation in ByteCoreStack MCP Connector for AI Tools. Brief link: https://feed.craftedsignal.io/briefs/2026-10-bytecorestack-mcp-privesc/

The ByteCoreStack - MCP Connector for AI Tools plugin for WordPress, in all versions up to and including 1.2.3, contains a critical privilege escalation vulnerability. The flaw exists within the execute_tool function when handling the wp_update_user_meta MCP tool. The implementation relies on current_user_can('edit_user', $uid) for authorization, which, when the target user ID matches the caller ID, defaults to the 'read' primitive. Furthermore, the plugin utilizes an insufficient blocklist for user meta keys, explicitly blocking user_pass, user_activation_key, and session_tokens, but failing to protect wp_capabilities and wp_user_level. Authenticated users with Subscriber access can exploit this to overwrite their own meta keys, granting themselves Administrator-level privileges. This issue poses a severe risk to WordPress instances utilizing this AI-connector plugin, as it facilitates full site compromise through unauthorized administrative access.

Impact

Successful exploitation of CVE-2026-19807 enables an authenticated Subscriber-level user to gain full Administrator control over the affected WordPress instance. This results in the potential for complete site takeover, including code execution via plugin installation, data exfiltration, and full database access. Given the nature of WordPress privileges, this vulnerability is critical for all installations currently using version 1.2.3 or earlier of the affected plugin.

Recommendation

  • Immediately audit current ByteCoreStack MCP Connector plugin versions and restrict usage of the plugin until a vendor patch addressing the improper meta key validation is applied.
  • Monitor web server logs for suspicious requests to MCP JSON-RPC endpoints that include parameters containing 'wp_capabilities' or 'wp_user_level' meta keys.
  • Enable security audit logging for user metadata updates to identify unauthorized elevation attempts.

Immediate actions

Inventory all WordPress instances running ByteCoreStack MCP Connector

SOC 24h

Mitigations

Disable ByteCoreStack MCP Connector plugin until a vendor security update is verified

immediate IT Operations

CVE-2026-19807

Detection coverage 1

Detects CVE-2026-19807 Exploitation - Unauthorized User Meta Update

high

Detects exploitation attempts targeting CVE-2026-19807 by looking for JSON-RPC requests containing restricted user meta keys like wp_capabilities or wp_user_level.

sigma tactics: privilege-escalation techniques: T1068 sources: webserver

Detection queries are available on the platform. Get full rules →