Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update the WordPress IATO MCP plugin to the latest available version (at least 1.12.1).
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Contributor Broken Access Control in IATO MCP <= 1.11.0 versions. | Missing Authorization vulnerability in iatoai IATO MCP iato-mcp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IATO MCP: from n/a through 1.12.0. |
| Title | WordPress IATO MCP plugin <= 1.11.0 - Broken Access Control vulnerability | WordPress IATO MCP plugin <= 1.12.0 - Broken Access Control vulnerability |
Tue, 06 Oct 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Contributor Broken Access Control in IATO MCP <= 1.11.0 versions. | |
| Title | WordPress IATO MCP plugin <= 1.11.0 - Broken Access Control vulnerability | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-10-08T18:47:48.687Z
Reserved: 2026-03-12T11:12:57.708Z
Link: CVE-2026-32582
Updated: 2026-10-06T10:31:44.926Z
Status : Deferred
Published: 2026-10-06T06:17:00.660
Modified: 2026-10-08T19:17:03.290
Link: CVE-2026-32582
No data.
OpenCVE Enrichment
Updated: 2026-10-08T08:00:16Z