Sceawere
Vulnerability Detail
CVE-2026-97239UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Subscriber Broken Access Control
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- Jose Conti
- Product
- MCP Content Manager Lite
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-09-30T13:17:35.617Z",
"pubdate": "2026-09-30T13:17:35.617Z",
"executiveSummary": "The MCP Content Manager Lite plugin for WordPress, specifically versions 1.1.0 and earlier, suffers from a critical Broken Access Control vulnerability. This flaw allows users with low-privileged subscriber accounts to perform unauthorized administrative actions, effectively bypassing intended security constraints within the plugin's architecture.\nThe vulnerability resides in the insufficient validation of user capabilities during critical request handling. An attacker possessing valid subscriber-level credentials can execute functions typically restricted to site administrators, leading to unauthorized content modification, configuration changes, or potential site takeover. This represents a significant security risk, as it effectively elevates the privileges of any registered user on the target installation. Exploitation does not require advanced technical sophistication but does necessitate authenticated access to the application. Given the nature of WordPress site ecosystems, the widespread availability of subscriber accounts makes this a high-impact threat that could lead to full site compromise and the exfiltration or destruction of sensitive information.",
"technicalDetails": "The root cause of this vulnerability is improper authorization handling within the MCP Content Manager Lite plugin. The application fails to adequately verify the current user's role or capabilities before processing sensitive requests or invoking administrative functions. In WordPress, developers are responsible for ensuring that functions performing sensitive operations are gated by current_user_can() checks, which verify the user's specific permissions (e.g., 'manage_options' or 'edit_posts'). The vulnerable component lacks these mandatory capability checks, allowing any authenticated session—regardless of the assigned user role—to access protected entry points.\nThe attack flow begins with an authenticated user identifying a request or endpoint exposed by the MCP Content Manager Lite plugin that triggers a backend operation. By crafting an HTTP request directed at these vulnerable functions, an attacker can bypass the intended restrictions. Since the server-side code relies solely on the presence of a session rather than validated permissions, it processes the request under the assumption that the caller is authorized. \nSpecifically, the lack of nonce validation or capability verification allows an attacker to manipulate plugin-specific parameters. For instance, if the plugin includes functions for updating system settings or modifying content, an attacker can submit a crafted request containing malicious payloads. Because the server does not enforce privilege boundaries, these requests are executed with the full context of the application, resulting in unauthorized administrative actions. \nThe impact of this broken access control is substantial. Post-exploitation, an attacker can leverage the plugin's features to modify plugin configuration, which could be used to facilitate further attacks, such as Cross-Site Scripting (XSS) through stored content, or potentially lead to remote code execution if the plugin allows file path manipulation or template modification. Furthermore, the attacker can leverage these elevated privileges to extract sensitive configuration data or manipulate site traffic. The vulnerability is strictly tied to the plugin's own API or backend controllers, affecting all versions up to and including 1.1.0. Because this is a logic-based flaw within the PHP implementation, network exposure is inherent to any site where this plugin is active, as the attacker simply requires a subscriber-level account to interact with the vulnerable endpoints."
}