{"id":"CVE-2026-96524","title":"The MCP Server for WordPress  WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attacker…","summary":"The MCP Server for WordPress  WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attacker…","severity":"none","cwe":["CWE-352"],"product":"MCP Server for WordPress","affected":["mcp_server_for_wordpress < 1.8.2"],"published":"2026-09-26","updated":"2026-09-26","sourceUpdated":"2026-09-26T07:17:03.130","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-96524","references":[{"url":"https://wpscan.com/vulnerability/d8e97a77-b70f-41f0-8d1e-0d50b6d878c6/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-26T06:27:03.684Z","slug":"CVE-2026-96524","body":"## Overview\n\nThe MCP Server for WordPress  WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attackers to perform administrator-only actions, including creating a new administrator account, by tricking a logged-in administrator into visiting a crafted page.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}