A WordPress MCP server plugin lets attackers add a rogue admin
MCP Server for WordPress had a CSRF flaw that let an attacker create a new administrator account just by getting a logged-in admin to click a link. Two lower-severity bugs were patched in the same release.