CVE-2026-19807 - ByteCoreStack <= 1.2.3 - Authenticated (Subscriber+) Privilege Escalation via wp_update_user_meta MCP Tool
CVE ID :CVE-2026-19807 Published : Oct. 1, 2026, 8:16 a.m. | 1 hour ago Description :The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the `wp_update_user_meta` MCP tool in...