{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/mountdev-ai/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-15015"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MountDev AI MCP Connector for WordPress plugin \u003c= 1.6.1","WordPress"],"_cs_severities":["critical"],"_cs_tags":["wordpress","authorization-bypass","cve","webserver","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["MountDev AI","WordPress Foundation"],"content_html":"\u003cp\u003eCVE-2026-15015 describes a critical authorization bypass vulnerability affecting all versions up to, and including, 1.6.1 of the MountDev AI MCP Connector for WordPress plugin. This flaw stems from inadequate verification of user authorization, enabling unauthenticated attackers to acquire an administrator-level OAuth Bearer token. Attackers can leverage a publicly accessible Dynamic Client Registration endpoint to register arbitrary OAuth clients with a controlled \u003ccode\u003eredirect_uri\u003c/code\u003e, then utilize an unprotected authorization endpoint to complete the OAuth flow without requiring any administrator interaction. This leads to full administrator-equivalent control over the plugin's MCP tool surface and, by extension, all exposed WordPress content, user data, and configuration options. The vulnerability carries a CVSS v3.1 Base Score of 9.8, indicating severe impact and ease of exploitation for any affected WordPress site.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker identifies a WordPress instance running the MountDev AI MCP Connector plugin.\u003c/li\u003e\n\u003cli\u003eThe attacker accesses the publicly exposed Dynamic Client Registration endpoint provided by the plugin.\u003c/li\u003e\n\u003cli\u003eThe attacker registers an arbitrary OAuth client by providing a malicious \u003ccode\u003eredirect_uri\u003c/code\u003e that they control.\u003c/li\u003e\n\u003cli\u003eThe attacker then initiates an OAuth authorization request using the newly registered client, leveraging an unprotected authorization endpoint within the plugin.\u003c/li\u003e\n\u003cli\u003eThe plugin processes the OAuth flow, completing it without requiring any legitimate administrator interaction or approval.\u003c/li\u003e\n\u003cli\u003eUpon successful completion of the OAuth flow, the attacker obtains a valid OAuth Bearer token.\u003c/li\u003e\n\u003cli\u003eThis token is administrator-bound, granting the attacker full administrator-equivalent access to the plugin's MCP tool surface.\u003c/li\u003e\n\u003cli\u003eThe attacker uses this access to modify or exfiltrate WordPress content, user data, and system options.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eA successful exploitation of CVE-2026-15015 grants unauthenticated attackers full administrative control over the affected WordPress installation via the MountDev AI MCP Connector. This allows for complete compromise of the website, including unauthorized access to sensitive data, modification or defacement of content, creation of new administrative users, and potential injection of malicious code. The high CVSS score of 9.8 reflects the ease of exploitation and the devastating consequences, posing a severe risk to data integrity, confidentiality, and availability for organizations utilizing the vulnerable plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the MountDev AI MCP Connector for WordPress plugin to a version patched against CVE-2026-15015.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to your SIEM to detect attempts at exploiting the Dynamic Client Registration endpoint.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for unusual POST requests to \u003ccode\u003e/wp-json/mountdev-ai-mcp-connector/v1/client/register\u003c/code\u003e or similar endpoints, particularly those containing suspicious \u003ccode\u003eredirect_uri\u003c/code\u003e parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T10:20:46Z","date_published":"2026-07-23T10:20:46Z","id":"https://feed.craftedsignal.io/briefs/2026-07-mountdev-ai-mcp-connector-auth-bypass/","summary":"An authorization bypass vulnerability, CVE-2026-15015, in all versions up to 1.6.1 of the MountDev AI MCP Connector for WordPress plugin allows unauthenticated attackers to obtain an administrator-bound OAuth Bearer token by exploiting publicly accessible client registration and an unprotected authorization endpoint, granting full administrator-equivalent access to the plugin's tool surface and WordPress content.","title":"MountDev AI MCP Connector WordPress Plugin Vulnerability Allows Unauthenticated Admin Access (CVE-2026-15015)","url":"https://feed.craftedsignal.io/briefs/2026-07-mountdev-ai-mcp-connector-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - MountDev AI","version":"https://jsonfeed.org/version/1.1"}