---
id: CVE-2026-96524
title: >-
  The MCP Server for WordPress  WordPress plugin before 1.8.2 does not correctly
  verify the WordPress REST API nonce for cookie-authenticated requests when a
  condition an attacker can influence is present, allowing unauthenticated
  attacker…
summary: >-
  The MCP Server for WordPress  WordPress plugin before 1.8.2 does not correctly
  verify the WordPress REST API nonce for cookie-authenticated requests when a
  condition an attacker can influence is present, allowing unauthenticated
  attacker…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-352
product: MCP Server for WordPress
affected:
  - mcp_server_for_wordpress < 1.8.2
published: '2026-09-26'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T23:16:40.770'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96524'
references:
  - url: 'https://wpscan.com/vulnerability/d8e97a77-b70f-41f0-8d1e-0d50b6d878c6/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-26T22:32:49.495318Z'
epss: 0.001
epssPercentile: 0.00793
ingestedAt: '2026-09-26T06:27:03.684Z'
---

## Overview

The MCP Server for WordPress  WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attackers to perform administrator-only actions, including creating a new administrator account, by tricking a logged-in administrator into visiting a crafted page.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
