CVE · High

CVE-2026-40775 — Royal MCP – Secure AI Connector for Claude, ChatGPT & any LLM via MCP [royal-mcp] < 1.4.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-40775 Royal MCP – Secure AI Connector for Claude, ChatGPT & any LLM via MCP [royal-mcp] < 1.4.3 Missing Authorization High 7.3 < 1.4.3 1.4.3 2026-04-21

CVE-2026-40775

The Royal MCP Secure AI Connector plugin for WordPress has a security flaw that allows unverified individuals to bypass standard access controls because a crucial capability check is absent from a specific function in versions prior to and including 1.4.2, enabling them to execute an illicit operation without proper authorization. This oversight creates a vulnerability through which unauthorized actions can be carried out by attackers who are not authenticated.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.