CVE

CVE-2026-10750 — Royal MCP – Secure AI Connector for Claude, ChatGPT & any LLM via MCP [royal-mcp] < 1.4.26

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-10750 Royal MCP – Secure AI Connector for Claude, ChatGPT & any LLM via MCP [royal-mcp] < 1.4.26 Missing Authorization Unknown < 1.4.26 1.4.26 2026-07-01

CVE-2026-10750

The Royal MCP WordPress plugin's security has been compromised in versions prior to 1.4.26 due to inadequate access control checks following successful authentication. As a result, users with limited privileges can gain unauthorized access to sensitive information and manipulate data belonging to others. This vulnerability affects the plugin's functionality, enabling malicious activities such as content tampering and user role discovery.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.