<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:bytecorestack:mcp_connector_for_ai_tools:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3abytecorestackmcp_connector_for_ai_tools/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 08:39:43 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3abytecorestackmcp_connector_for_ai_tools/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-19807 Privilege Escalation in ByteCoreStack MCP Connector for AI Tools</title><link>https://feed.craftedsignal.io/briefs/2026-10-bytecorestack-mcp-privesc/</link><pubDate>Thu, 01 Oct 2026 08:39:43 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-bytecorestack-mcp-privesc/</guid><description>The ByteCoreStack MCP Connector for AI Tools plugin for WordPress is vulnerable to privilege escalation via insufficient meta key validation, allowing Subscriber-level users to escalate to Administrator.</description><content:encoded><![CDATA[<p>The ByteCoreStack - MCP Connector for AI Tools plugin for WordPress, in all versions up to and including 1.2.3, contains a critical privilege escalation vulnerability. The flaw exists within the <code>execute_tool</code> function when handling the <code>wp_update_user_meta</code> MCP tool. The implementation relies on <code>current_user_can('edit_user', $uid)</code> for authorization, which, when the target user ID matches the caller ID, defaults to the 'read' primitive. Furthermore, the plugin utilizes an insufficient blocklist for user meta keys, explicitly blocking <code>user_pass</code>, <code>user_activation_key</code>, and <code>session_tokens</code>, but failing to protect <code>wp_capabilities</code> and <code>wp_user_level</code>. Authenticated users with Subscriber access can exploit this to overwrite their own meta keys, granting themselves Administrator-level privileges. This issue poses a severe risk to WordPress instances utilizing this AI-connector plugin, as it facilitates full site compromise through unauthorized administrative access.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-19807 enables an authenticated Subscriber-level user to gain full Administrator control over the affected WordPress instance. This results in the potential for complete site takeover, including code execution via plugin installation, data exfiltration, and full database access. Given the nature of WordPress privileges, this vulnerability is critical for all installations currently using version 1.2.3 or earlier of the affected plugin.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately audit current ByteCoreStack MCP Connector plugin versions and restrict usage of the plugin until a vendor patch addressing the improper meta key validation is applied.</li>
<li>Monitor web server logs for suspicious requests to MCP JSON-RPC endpoints that include parameters containing 'wp_capabilities' or 'wp_user_level' meta keys.</li>
<li>Enable security audit logging for user metadata updates to identify unauthorized elevation attempts.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>privilege-escalation</category><category>web-application</category></item></channel></rss>