CVE-2026-10750

HIGH

Royal MCP < 1.4.26 - Subscriber+ Insufficient Authorization in MCP Tools

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-10750. PoCs published by HermesNA-1.

AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-10750, a missing capability check vulnerability in the Royal MCP WordPress plugin (before 1.4.26). The module includes placeholder code for probing the target but lacks actual exploit implementation for privilege escalation via unauthenticated MCP tool access.

Description

The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP tools after token authentication, allowing authenticated users with a low-privileged role such as Subscriber to read private content, enumerate all users and their roles, and create, modify, or delete content owned by other users.

Exploits (1)

github STUB 1 stars
by HermesNA-1 · pythonpoc
https://github.com/HermesNA-1/SnakeSploit/tree/main/data/modules_generated/cve-2026-10750_the_royal_mcp.py

This repository contains an auto-generated stub module for CVE-2026-10750, a missing capability check vulnerability in the Royal MCP WordPress plugin (before 1.4.26). The module includes placeholder code for probing the target but lacks actual exploit implementation for privilege escalation via unauthenticated MCP tool access.

Classification
Stub 99%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Theoretical
Target: The Royal MCP WordPress plugin before 1.4.26
Auth required
Prerequisites: Low-privileged authenticated access to WordPress · Target running vulnerable Royal MCP plugin version
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/8678ef91-ff05-43a1-a8e3-6d35da548826/

Scores

CVSS v3 8.1
EPSS 0.0027
EPSS Percentile 18.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

Status published
Products (1)
None/Royal MCP < 1.4.26
Published Jul 01, 2026
Tracked Since Jul 01, 2026