100,000+ WordPress Sites Vulnerable to Privilege Escalation via MCP AI Engine
ID: 1509f36e-68cc-5413-a86c-143538a3cdfe
STIX ID: report--1509f36e-68cc-5413-a86c-143538a3cdfe
Feed Name: Cyber Press
Threat Score
A critical vulnerability (CVE-2025-5071) in the AI Engine WordPress plugin (v2.8.0–2.8.3) allows authenticated low-privilege users to access MCP endpoints due to faulty can_access_mcp() authorization and an insecure Bearer Token fallback, enabling privilege escalation to administrator and full site compromise; the developer released a patch in v2.8.4 and Wordfence issued firewall protections while urging immediate updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
