CyberRota Analysis
AI-GeneratedThe MCP Server plugin for WordPress prior to version 1.8.2 is vulnerable due to improper verification of the WordPress REST API nonce for cookie-authenticated requests, which can be exploited by unauthenticated attackers. This flaw allows attackers to perform administrator-level actions, such as creating new administrator accounts, by deceiving a logged-in administrator into accessing a malicious page. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of unauthorized access.
Original NVD Description
The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attackers to perform administrator-only actions, including creating a new administrator account, by tricking a logged-in administrator into visiting a crafted page.