WP Vulnerability WatchVulnerability data as of October 1, 2026

Known vulnerabilities in MCP Server for WordPress – Connect Claude, ChatGPT & Gemini | AtlasMCP

Secure MCP server for WordPress. Connect Claude, ChatGPT & Gemini via OAuth 2.1. Unlimited AI abilities, WooCommerce tools, RBAC, editor AI.

3Reported vulnerabilities
4.3Highest CVSS score
1.9.0Latest version
200+Active installs

What to do now

Update MCP Server for WordPress – Connect Claude, ChatGPT & Gemini | AtlasMCP to 1.8.2 or later. 3 of these have a fixed version available. Updating resolves them.

Plugin last updated: September 30, 2026 / Tested up to WordPress: 7.1.2 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2026-96525 Medium 4.3 0.2% 1.8.1 and earlier 1.8.2 September 24, 2026
CVE-2026-96526 Medium 4.3 0.2% 1.8.1 and earlier 1.8.2 September 24, 2026
CVE-2026-96524 Medium 4.3 0.1% 1.8.1 and earlier 1.8.2 September 24, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.