MountDev AI MCP Connector for WordPress: Critical Vulnerability Reported
The MountDev AI MCP Connector for WordPress plugin <=1.6.1 reportedly has a critical vulnerability allowing unauthenticated attackers to gain administrator-equivalent access.
What happened
An early warning has been issued regarding a critical vulnerability in the MountDev AI MCP Connector for WordPress plugin. Reportedly, all versions up to and including 1.6.1 are affected. The vulnerability, tracked as CVE-2026-15015, appears to allow unauthenticated attackers to bypass authorization and obtain an administrator-bound OAuth Bearer token. This token would grant full administrator-equivalent access to the plugin's tool surface and all exposed WordPress content, users, and options.
The vulnerability is under investigation and is believed to be exploitable by combining the Dynamic Client Registration endpoint with the unprotected authorization endpoint. This allows unauthenticated callers to register arbitrary OAuth clients and complete the full OAuth flow without administrator interaction.
Professionals using the MountDev AI MCP Connector for WordPress should closely monitor updates from primary sources and be prepared to upgrade to a patched version once available. For the latest information and detailed technical analysis, consult the NVD page for CVE-2026-15015.
How 0Day mitigates this
mountdev ai mcp connector is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.