Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini

Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2026; all 2 are fixed as of August 2026. Their average CVSS score is 4.8, and the most serious one scores 5.3 out of 10. 2026 was the busiest year with 2 disclosures.

The most common weakness is Missing Authorization, behind 2 of the records (100%).

Every one of the 2 issues recorded for Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
4.8/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.3CVE-2026-40775

Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini <= 1.4.2 - Missing Authorization

Read the full analysis

Vulnerability Records

2 records
Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini banner
Latestv1.4.40

Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini

Royal Plugins

Author

Royal Plugins

5.0(7)
100/100
Last Updated
2026-08-12 (3d ago)
Active Installs
10,000+
Downloads
77,486
Requires WP
5.8+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2026-01-14 (7mo ago)

Royal MCP is a security-first Model Context Protocol (MCP) server for WordPress. It gives AI platforms like Claude, ChatGPT, and Google Gemini structured access to your WordPress content — with authentication, rate limiting, and audit logging that most MCP implementations skip entirely. First-time setup walkthrough (with videos): royalplugins.com/support/royal-mcp/connecting-to-claude/ According to recent security research, 41% of public MCP servers have no authentication and respond to tool calls without any credentials. Royal MCP takes the opposite approach: every MCP session requires an API key, every request is rate-limited, and every interaction is logged. Why Security Matters for MCP MCP gives AI agents the ability to read, create, update, and delete your WordPress content. Without proper authentication, anyone who discovers your MCP endpoint can: Read all your posts, pages, and media Create or delete content Access user data and plugin information Overwhelm your server with rapid-fire requests Royal MCP prevents all of this with API key authentication on session initialization, timing-safe key comparison, per-IP rate limiting (60 requests/minute), and a full activity log of every MCP interaction. Free, Self-Hosted, Fully Featured Royal MCP is fully featured in its free, GPL-licensed release. There is no Pro version &mdash; all tools ship in the wp.org plugin, and updates go through the standard WordPress plugin updater. Your credentials stay on your server. Royal MCP runs entirely inside WordPress: API keys, OAuth tokens, and session state all live in your own database. Royal MCP makes no outbound connections to Royal Plugins&rsquo; own servers &mdash; no license check, no telemetry, no traffic beacon. If you prefer to keep AI inference local too, Ollama and LM Studio are first-class platforms alongside Claude, ChatGPT, and Gemini. See What AI Agents Do With Your Site Royal MCP connects AI agents to WordPress. The free Royal AI Firewall companion shows you every AI agent hitting your site at the HTTP layer &mdash; training crawlers, retrieval bots, AI search engines &mdash; not just the ones connected through Royal MCP. Install both for a unified audit trail: MCP tool calls and HTTP-layer bot hits appear side by side in one dashboard, with per-bot allow / block / log-only controls for 60+ recognized AI agents. Royal AI Firewall is free forever, no upgrade prompt. 81 Core Tools + 74 Integration Tools WordPress Core (81 tools): Posts – create, read, update, delete, search, count (any registered public post type, featured images supported) Pages – full CRUD with parent page support Post Types – discover all registered public post types on the site Post Revisions – list revision history and roll a post back to any prior version Media – browse, upload from URL or base64, update alt text/caption/title/description, set as featured image, delete Comments – create, read, delete; full moderation suite (list pending, approve, mark spam, trash) Users – display names and roles (emails and usernames are not exposed) Categories & Tags & Custom Taxonomies – create, update (rename/re-slug/edit/move), delete, assign, count, discover all registered taxonomies Term Meta – read, update, delete (most useful for term-level SEO meta – titles, descriptions, focus keywords stored against categories and tags) Menus – list menus, list menu items, create / update / delete / reorder menu items Post Meta – read, update, delete custom fields (works with ACF, MetaBox, JetEngine, Pods, CPT UI) SEO Meta – read and write Yoast SEO, Rank Math, AIOSEO, or SEObolt title/description/focus keyword/robots/OG fields (auto-detects active SEO plugin) SEO Audit – fetch a post’s actual rendered HTML and report title, meta description, canonical, viewport, Open Graph and Twitter Card tags (catches conflicts that only appear in served output) Widgets – list widget instances (optionally filtered by sidebar), list registered sidebars, and update widget content; writes gated by the theme-appearance admin toggle Find and Replace – literal find/replace inside post/page content with dry-run preview, expected-count safety check, and read-after-write verification Undo – reverse the previous delete or reorder within 72 hours via mcp_undo_last_operation Site Info – site name, description, WordPress version, timezone Site Status – full site health snapshot (WordPress version, PHP version, active theme, active plugins, cron activity) for AI-driven pre-write validation Error Log – read recent PHP error log entries so AI agents can diagnose silent failures without shell access Cron Schedule – list scheduled WP cron events with next-run timestamps and hook names Connection Health – MCP session diagnostic returning route, auth method, session ID, and Royal MCP version details for any authenticated caller Plugins & Themes – list installed plugins and themes with active status Theme Appearance – get active theme, read/write theme mods (gated by admin toggle + allowlist), read/write Custom CSS Search – full-text content search across post types Permalink Structure – read and update permalink settings (gated by admin toggle) Options – read allowlisted core options, read full plugin settings by slug (sensitive keys redacted), and write to allowlisted options when an admin enables it Plugin Integrations (Conditional) Royal MCP automatically detects compatible plugins and adds specialized MCP tools. No configuration needed — if the plugin is active, the tools appear. WooCommerce Integration (29 tools): When WooCommerce is active, AI agents can manage your store end-to-end: Browse and search products by category, status, or type Create and update simple and variable products with prices, SKUs, stock levels Manage variable products — list, get, create, update, delete, and batch-update product variations Manage global attributes (pa_* taxonomies) — list registered attributes, list attribute terms, register new attributes, assign attributes to a product as variation axes Manage coupons — list, search by code, get, create, update, delete (trash or permanent), and bulk-purge trash; supports all standard WC coupon fields (discount type, expiry, usage limits, product/category restrictions, email allowlists) View orders, order details, and update order status Create and update orders and attach order notes — for B2B, wholesale, phone orders, and support-note trails List customers with order count and total spent Get store statistics — revenue, order count, average order value by period Elementor Integration (8 tools): When Elementor (free or Pro) is active, AI agents can clone and customize existing Elementor pages without trying to generate page-builder JSON from scratch: Clone an existing Elementor page with a new title and fresh element IDs (so the duplicate opens in the editor without ID collisions) Bulk-replace text across heading, text-editor, button, image-box, icon-box, icon-list, testimonial, tabs, accordion, toggle, star-rating, call-to-action, and flip-box widgets Swap image URLs across image, image-box, background_image, and gallery widget settings Get a compact outline of any page (section/container hierarchy, widget types, text snippets) so Claude can reason over a full page in a few KB instead of the raw JSON Read full settings for a single widget/container/section/column by ID (for precise agent editing without loading the entire page tree) List saved templates from the Elementor template library and import templates from JSON Atomic widgets (Elementor 4.0+ Editor V4 elements) pass through opaque — we never decode atomic schemas because Elementor itself may shift them. Widget-level creation from scratch is intentionally out of scope; the design commitment is to work from an existing-known-good source. Advanced Custom Fields Integration (4 tools): When ACF (free or Pro) is active, AI agents can read and write ACF fields with the field-type-aware formatting the ACF UI uses — instead of the raw serialized values WordPress meta returns: Read a single ACF field, formatted per its Return Format setting (hydrated post objects, parsed repeater rows, image arrays, etc.) Read every ACF field on a post in one call, with name/label/type/value bundled — the most efficient way for an AI to discover what fields exist and read them all Update an ACF field with type-aware value handling (scalar for text/number, array for repeaters and flex content, post ID for relationships, attachment ID for images) Enumerate ACF field groups on the site, optionally filtered by post type — for AI-driven discovery of available custom fields before reading/writing GuardPress Integration (7 tools): When GuardPress is active, AI agents can monitor your site security: Get current security score and grade with factor breakdown View security statistics — failed logins, blocked IPs, alerts Run vulnerability scans and review results List blocked IP addresses and failed login attempts Browse the security audit log filtered by severity Royal AI Firewall Integration (6 tools): When the free Royal AI Firewall companion is installed, Royal MCP gets full observability over every AI agent hitting your site &mdash; not just MCP callers. AI agents connected through Royal MCP can also review bot traffic and update policies via 6 additional tools: View dashboard statistics — total hits, unique bots, top bots, top paths across the site Get recent bot hits with per-bot detail, timestamps, and requested paths List AI bot policies (allow, block, or challenge) per known bot signature Update AI bot policies (admin-only) to allow, block, or challenge any known signature Get daily rollups — traffic aggregates by bot over the past N days for trend detection Block all AI bots in one call — emergency lockdown covering every known AI-agent signature at once SiteVault Integration (6 tools): When SiteVault is active, AI agents can manage your backups: List available backups filtered by status or type Trigger new backups (full, database, files, plugins, themes) Check backup progress in real time View backup statistics — total size, last backup, counts List and review backup schedules ForgeCache Integration (3 tools): When ForgeCache is active, AI agents can manage your page cache: Clear the entire cache, or purge a specific URL View cache statistics — hit rate, file count, total size Royal Ledger Integration (4 tools): When Royal Ledger is active, AI agents can review your software costs and license data: List recurring software costs and renewal dates Get cost summaries grouped by month, vendor, or category List stored license keys (key VALUES are never exposed — only masked previews; decryption requires logging into wp-admin) Royal Links Integration (3 tools): When Royal Links is active, AI agents can manage your branded short links: List existing links with click counts and target URLs Create new branded short links Get click statistics for any link Redirection Integration (4 tools): When John Godley’s Redirection plugin is active, AI agents can manage 301 / 302 / 307 redirects: List redirects with group + URL-substring filters Create new redirects (source, target, status code, regex, group, title) Update existing redirects (target, status, enabled state) List redirect groups Royal MCP and the WordPress Core Abilities API WordPress 6.9 shipped the Abilities API in November 2025 — a primitive that lets plugins register typed capabilities AI agents can call. Core ships three default abilities (site info, user info, environment info) and the wordpress/mcp-adapter package bridges abilities to the MCP protocol. As of 1.4.38, every Royal MCP tool also registers as a WordPress ability. You get three ways to reach the same tools: (1) Royal MCP’s native /wp-json/royal-mcp/v1/mcp endpoint (unchanged and always available), (2) the WordPress MCP Adapter if you install it — Royal MCP registers a named royal-mcp-server alongside adapter’s default server, or (3) WordPress core REST directly at /wp-json/wp-abilities/v1/abilities/{name}/run. Same handlers, three transports, one set of per-tool capability gates. The abilities layer can be disabled with a single option flag if needed. Royal MCP is a complete, production-ready MCP server that predates the official adapter. It runs the full Streamable HTTP transport, enforces API key authentication on every request, ships OAuth 2.0 for Claude Desktop’s native connector flow, rate-limits per-IP, redacts sensitive data, and logs every interaction. Out of the box it includes 81 tools for WordPress core operations plus 74 integration tools that auto-load when WooCommerce, GuardPress, Royal AI Firewall, SiteVault, ForgeCache, Royal Ledger, Royal Links, Elementor, Advanced Custom Fields (ACF), or Redirection is active. Supported AI Platforms Claude (Anthropic) – Full MCP support via Claude Desktop, Claude Code, and VS Code OpenAI / ChatGPT – GPT-5.5, GPT-5, GPT-5 Mini, o3 Google Gemini – Gemini 3.5 Flash, 3.1 Flash-Lite Groq – Llama 3.3, Llama 3.1, GPT-OSS Azure OpenAI – Azure-hosted OpenAI deployments AWS Bedrock – Claude, Llama, Titan models Ollama / LM Studio – Local self-hosted models (no external data transmission) Custom MCP Servers – Connect to any MCP-compatible endpoint Compatible Clients & Frameworks Royal MCP works with any MCP-compliant client, IDE, or AI agent framework — no per-tool configuration required. Each entry below describes the specific integration path Royal MCP provides for that target, so customers can answer “will this work with the tool I already use?”: Desktop AI apps – Claude Desktop (native MCP connector via OAuth 2.0), ChatGPT Desktop, Gemini Advanced. AI code IDEs – Claude Code, VS Code (with MCP extension), Cursor, Windsurf, Continue, Cline, Zed, JetBrains AI Assistant. API testing tools – Postman, Bruno, Insomnia (use the API key in the X-Royal-MCP-API-Key header). Custom field plugins – Advanced Custom Fields (ACF) has dedicated acf_* tools that return values formatted per each field’s Return Format setting (the same way the ACF UI shows them). MetaBox, JetEngine, Pods, CPT UI, and Custom Field Suite are supported through the wp_get_post_meta / wp_update_post_meta tools, so AI agents can populate custom fields just like a human editor. Page builders – Elementor has dedicated tools for clone-and-customize workflows (clone a page, find/replace text, swap images, get an outline, import templates) – see the Tools list. Widget-level creation from scratch is intentionally out of scope. Divi, Beaver Builder, Bricks, Gutenberg, Spectra, and Stackable store standard post content that is readable and writable by AI; page-builder-specific JSON storage is opaque unless covered by a dedicated tool. Multilingual – WPML, Polylang, TranslatePress, qTranslate. Translated posts appear as separate posts and can be read or written via the standard post tools. AI agent frameworks – LangChain, AutoGen, CrewAI, LlamaIndex, Haystack – any MCP-compatible framework can call Royal MCP’s tools. AI app platforms – Anthropic Console, OpenAI Playground, Google AI Studio, Vertex AI, Azure AI Studio, Amazon Bedrock Console. MCP Spec Compliance Royal MCP implements the MCP 2025-11-25 Streamable HTTP transport specification: Single /mcp endpoint for all JSON-RPC communication POST for client messages, GET for server-sent events, DELETE for session termination Cryptographically secure session IDs with transient-based storage Origin header validation to prevent DNS rebinding attacks Proper CORS handling for browser-based MCP clients External Services This plugin connects to third-party AI services to enable AI platforms to interact with your WordPress content. No data is transmitted until you explicitly configure and enable a platform connection. **What &hellip;

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C