A WordPress MCP server plugin lets attackers add a rogue admin
MCP Server for WordPress had a CSRF flaw that let an attacker create a new administrator account just by getting a logged-in admin to click a link. Two lower-severity bugs were patched in the same release.
MCP Server for WordPress, a plugin that exposes a site’s admin actions to AI agents over the Model Context Protocol, patched a CSRF bug on 26 September that let an attacker create a new administrator account. It’s fixed in 1.8.2; every earlier version is affected.
CVE-2026-96524 (CVSS 8.8) is a missing nonce check: the plugin’s REST API is meant to verify that a cookie-authenticated request actually came from the logged-in user, but under a condition an attacker can influence, that check doesn’t fire. Trick a logged-in admin into visiting a crafted page and the attacker gets admin-only actions, including new account creation, with no credentials of their own. Two lower-severity bugs fixed in the same release let Contributor-level users read and tamper with workflow configuration meant to be admin-only, including other users’ unpublished posts.
Why it matters: the entire point of plugging an MCP server into WordPress is to let an AI agent act on the site without a human approving every step. A CSRF hole in the layer that’s supposed to gate those actions defeats that model more thoroughly than it would in an ordinary plugin. If you’ve connected an agent to WordPress this way, update to 1.8.2.
The caveat: it needs a logged-in administrator to visit the attacker’s page, it isn’t exploitable pre-auth. EPSS puts 30-day exploitation probability at 0.1%, and there’s no report of active abuse yet.