logo

100,000+ WordPress Sites Vulnerable to Privilege Escalation via MCP AI Engine

ID: 1509f36e-68cc-5413-a86c-143538a3cdfe

STIX ID: report--1509f36e-68cc-5413-a86c-143538a3cdfe

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2025-06-19

Date Updated: 2026-04-13

Author: Mandvi

...
...

A critical vulnerability (CVE-2025-5071) in the AI Engine WordPress plugin (v2.8.0–2.8.3) allows authenticated low-privilege users to access MCP endpoints due to faulty can_access_mcp() authorization and an insecure Bearer Token fallback, enabling privilege escalation to administrator and full site compromise; the developer released a patch in v2.8.4 and Wordfence issued firewall protections while urging immediate updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.