WP Clinic
Log in Sign up

CVE · High

CVE-2026-54842 — Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini [royal-mcp] < 1.4.26

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-54842 Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini [royal-mcp] < 1.4.26 Missing Authorization High 8.1 < 1.4.26 1.4.26 2026-06-18

CVE-2026-54842

The Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.4.25. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

Source: Wordfence

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.