What is CVE-2026-15015?
CVE-2026-15015 is an authorization bypass vulnerability in the MountDev AI MCP Connector for WordPress plugin, affecting all versions up to and including 1.6.1. This flaw allows unauthenticated attackers to perform unauthorized actions due to improper user capability verification. Users should update the plugin to the latest patched version immediately.
Azərbaycanca: CVE-2026-15015 MountDev AI MCP Connector for WordPress plaginində avtorizasiya bypass zəifliyidir. 1.6.1-ə qədər olan bütün versiyalar təsirlənir və identifikasiya olunmamış hücumçulara icazəsiz əməliyyatlar aparmağa imkan verir. Plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of the MountDev AI MCP Connector for WordPress plugin are affected by CVE-2026-15015?
All versions up to and including 1.6.1 are affected by this vulnerability.
What can attackers do by exploiting CVE-2026-15015?
Unauthenticated attackers can perform unauthorized actions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.