Agentimus WordPress Plugin Broken Access Control (Subscriber Privilege Escalation)
highAgentPrivilege AbuseA WordPress plugin that exposes an MCP interface and llms.txt generation for AI agents contains a broken access control flaw allowing low-privileged Subscriber-level users to perform actions reserved for higher-privilege roles. This could let an attacker with minimal site access escalate privileges or manipulate AI-agent-facing configuration and content. No evidence of active exploitation is provided in the raw data, but the CVSS score indicates meaningful impact if exploited.
Updated Sep 3, 2026 · CVSS 8.1