Skip to content
MindPattern
Wire
Briefings
Search
Subscribe
← The Wire
Source trail
WPScan / NVD
Public MindPattern findings, entities, and graph evidence that cite this source.
Findings
1
All-time hits
1
High value
0
Last seen
2026-09-26
Related findings
2026-09-26 / TOOLS
AtlasMCP WordPress plugin: CSRF bug let a malicious link make a logged-in admin create a new administrator (CVE-2026-96524, CVSS 8.8)
NVD published three CVEs on 09-26 against the 'MCP Server for WordPress' plugin (now AtlasMCP) before 1.8.2. In one, a crafted page visited by a logged-in admin could create an administrator account through the REST API. The other two let Contributor-role users change site-wide workflows and read private post titles. The fix shipped 09-23, and wordpress.org lists only about 200 active installs, so the risk is small, but the bug class applies to any site-hosted MCP bridge using cookie auth.
Open latest cited source
Wire
Briefings
Search
Subscribe