Royal Plugins Royal MCP是Royal Plugins公司的一款将 WordPress 网站转变为模型上下文协议(MCP)服务器的插件。它能够将网站与 Claude、ChatGPT、Google Gemini 等人工智能大模型及客户端安全地连接起来。 Royal Plugins Royal MCP 1.4.26之前版本存在授权问题漏洞,该漏洞源于令牌认证后未对MCP工具执行权限检查,导致低权限经过身份验证的用户可读取私有内容、枚举所有用户及其角色,以及创建、修改或删除其他用户拥有的内容
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11568 | Product Configurator for WooCommerce < 1.7.3 - Unauthenticated Private/Draft Product Data | |
| CVE-2026-11562 | WS Form LITE < 1.11.8 - Subscriber+ Arbitrary Settings Update | |
| CVE-2026-11570 | User Submitted Posts < 20260608 - Unauthenticated Stored XSS via Author Name | |
| CVE-2026-11794 | Advanced Form Integration < 2.1.1 - Unauthenticated Privilege Escalation via Breakdance Fo | |
| CVE-2026-11887 | Salon Booking System < 10.30.20 - Subscriber+ Booking Approval Bypass | |
| CVE-2026-11880 | Fluent Forms < 6.2.1 - Subscriber+ Subscription Cancellation via IDOR | |
| CVE-2026-11883 | WebAuthn Provider for Two Factor < 2.5.6 - 2FA Bypass |
No comments yet