CVE-2026-19807 | ByteCoreStack Plugin up to 1.2.3 on WordPress MCP Tool execute_tool uid privileges management

SecurityVulns

A vulnerability was found in ByteCoreStack Plugin up to 1.2.3 on WordPress. It has been rated as problematic. The affected element is the function execute_tool of the component MCP Tool. The manipulation of the argument uid leads to improper privilege management.

This vulnerability is uniquely identified as CVE-2026-19807. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More