CVE-2026-10750
HIGHRoyal MCP < 1.4.26 - Subscriber+ Insufficient Authorization in MCP Tools
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-10750. PoCs published by HermesNA-1.
AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-10750, a missing capability check vulnerability in the Royal MCP WordPress plugin (before 1.4.26). The module includes placeholder code for probing the target but lacks actual exploit implementation for privilege escalation via unauthenticated MCP tool access.
Description
The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP tools after token authentication, allowing authenticated users with a low-privileged role such as Subscriber to read private content, enumerate all users and their roles, and create, modify, or delete content owned by other users.
Exploits (1)
This repository contains an auto-generated stub module for CVE-2026-10750, a missing capability check vulnerability in the Royal MCP WordPress plugin (before 1.4.26). The module includes placeholder code for probing the target but lacks actual exploit implementation for privilege escalation via unauthenticated MCP tool access.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N