CVE-2026-15015
The MountDev AI MCP Connector for WordPress plugin is vulnerable to an authorization bypass that lets anyone register an OAuth client and obtain an administrator‑level token. This flaw exists in all versions up to 1.6.1 and can be exploited without any user interaction.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
MountDev AI MCP Connector for WordPress plugin for WordPress, versions 1.6.1 and earlier.
Real-world impact
An attacker can gain full administrator access to the plugin and all WordPress content, users, and settings, effectively taking over the site.
Why this severity
The CVSS score of 9.8 reflects that the flaw is exploitable from the internet, requires no authentication, and gives complete control over the application, leading to confidentiality, integrity, and availability compromise.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources