PLUGIN SECURITY

Is Royal Mcp safe?

170+ MCP tools. OAuth 2.0. Connect Claude, ChatGPT, Gemini, Cursor & any MCP agent to your WordPress site. 100% self-hosted.

What this plugin does

  • Slug: royal-mcp
  • Author: Royal Plugins
  • 10000+ active installs
  • 100/100 rating (7 reviews on wordpress.org)
  • 92118 all-time downloads
  • On WordPress.org since 2026-01-14

AIChatGPTClaudeelementormcp

Maintenance status

  • Latest known version: 1.4.39
  • Last updated: 2026-08-24 7:22am GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

3 known CVEs on file for Royal Mcp. Reported between 2026 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-10750 Royal MCP – Secure AI Connector for Claude, ChatGPT & any LLM via MCP [royal-mcp] < 1.4.26 Missing Authorization Unknown < 1.4.26 1.4.26 2026-07-01 ✓ fixed in latest
CVE-2026-54842 Royal MCP – Secure AI Connector for Claude, ChatGPT & any LLM via MCP [royal-mcp] < 1.4.26 Missing Authorization High 8.1 < 1.4.26 1.4.26 2026-06-18 ✓ fixed in latest
CVE-2026-40775 Royal MCP – Secure AI Connector for Claude, ChatGPT & any LLM via MCP [royal-mcp] < 1.4.3 Missing Authorization High 7.3 < 1.4.3 1.4.3 2026-04-21 ✓ fixed in latest

How to fix it

Keep Royal Mcp updated — 1.4.39 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.