{"id":285474,"date":"2026-03-31T11:33:17","date_gmt":"2026-03-31T11:33:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/easy-mcp-connector\/"},"modified":"2026-09-20T08:46:30","modified_gmt":"2026-09-20T08:46:30","slug":"mountdev-ai-mcp-connector","status":"publish","type":"plugin","link":"https:\/\/tw.wordpress.org\/plugins\/mountdev-ai-mcp-connector\/","author":18139870,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.6.9","stable_tag":"1.6.9","tested":"7.0.5","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"MountDev AI MCP Connector for WordPress","header_author":"cascadiawebservices","header_description":"Transform your WordPress site into an AI-powered Model Context Protocol (MCP) server. Exposes WordPress functionality through a standardized interface for AI agents.","assets_banners_color":"919191","last_updated":"2026-09-20 08:46:30","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/cascadiaweb.services\/products\/mountdev\/easy-mcp-connector","header_author_uri":"https:\/\/cascadiaweb.services","rating":0,"author_block_rating":0,"active_installs":100,"downloads":3121,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"cascadiawebservices","date":"2026-03-31 11:32:32","revision":3495494},"1.1.0":{"tag":"1.1.0","author":"cascadiawebservices","date":"2026-04-13 11:00:38","revision":3505067},"1.1.1":{"tag":"1.1.1","author":"cascadiawebservices","date":"2026-04-14 09:03:28","revision":3505886},"1.2.0":{"tag":"1.2.0","author":"cascadiawebservices","date":"2026-04-27 12:21:00","revision":3516433},"1.3.2":{"tag":"1.3.2","author":"cascadiawebservices","date":"2026-05-05 15:51:06","revision":3523568},"1.4.0":{"tag":"1.4.0","author":"cascadiawebservices","date":"2026-05-08 13:25:54","revision":3526572},"1.5.0":{"tag":"1.5.0","author":"cascadiawebservices","date":"2026-05-14 09:54:09","revision":3531806},"1.5.1":{"tag":"1.5.1","author":"cascadiawebservices","date":"2026-05-20 13:36:43","revision":3539417},"1.5.2":{"tag":"1.5.2","author":"cascadiawebservices","date":"2026-05-21 12:42:06","revision":3541962},"1.6.0":{"tag":"1.6.0","author":"cascadiawebservices","date":"2026-07-02 10:25:16","revision":3593778},"1.6.2":{"tag":"1.6.2","author":"cascadiawebservices","date":"2026-07-09 12:04:38","revision":3601448},"1.6.3":{"tag":"1.6.3","author":"cascadiawebservices","date":"2026-07-09 12:50:56","revision":3601498},"1.6.4":{"tag":"1.6.4","author":"cascadiawebservices","date":"2026-07-20 12:31:09","revision":3614732},"1.6.5":{"tag":"1.6.5","author":"cascadiawebservices","date":"2026-07-22 11:05:14","revision":3618471},"1.6.6":{"tag":"1.6.6","author":"cascadiawebservices","date":"2026-09-02 11:12:44","revision":3677846},"1.6.7":{"tag":"1.6.7","author":"cascadiawebservices","date":"2026-09-18 08:37:41","revision":3701599},"1.6.8":{"tag":"1.6.8","author":"cascadiawebservices","date":"2026-09-20 07:51:28","revision":3703992},"1.6.9":{"tag":"1.6.9","author":"cascadiawebservices","date":"2026-09-20 08:46:30","revision":3704042}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3495494,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3495494,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3495494,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3495494,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.1.0","1.1.1","1.2.0","1.3.2","1.4.0","1.5.0","1.5.1","1.5.2","1.6.0","1.6.2","1.6.3","1.6.4","1.6.5","1.6.6","1.6.7","1.6.8","1.6.9"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3531806,"resolution":"1","location":"assets","locale":"","width":1143,"height":1080},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3531806,"resolution":"2","location":"assets","locale":"","width":1139,"height":1013},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3531806,"resolution":"3","location":"assets","locale":"","width":1145,"height":1086},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3531806,"resolution":"4","location":"assets","locale":"","width":1269,"height":1121},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3531806,"resolution":"5","location":"assets","locale":"","width":1140,"height":1117},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3531806,"resolution":"6","location":"assets","locale":"","width":1143,"height":680},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3531806,"resolution":"7","location":"assets","locale":"","width":1135,"height":774}},"screenshots":[]},"plugin_section":[],"plugin_tags":[2353,232494,216196,229563,242115],"plugin_category":[38],"plugin_contributors":[249506],"plugin_business_model":[],"class_list":["post-285474","plugin","type-plugin","status-publish","hentry","plugin_tags-ai","plugin_tags-ai-agent","plugin_tags-chatgpt","plugin_tags-claude","plugin_tags-mcp","plugin_category-authentication","plugin_contributors-cascadiawebservices","plugin_committers-cascadiawebservices"],"banners":{"banner":"https:\/\/ps.w.org\/mountdev-ai-mcp-connector\/assets\/banner-772x250.png?rev=3495494","banner_2x":"https:\/\/ps.w.org\/mountdev-ai-mcp-connector\/assets\/banner-1544x500.png?rev=3495494","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/mountdev-ai-mcp-connector\/assets\/icon-128x128.png?rev=3495494","icon_2x":"https:\/\/ps.w.org\/mountdev-ai-mcp-connector\/assets\/icon-256x256.png?rev=3495494","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/mountdev-ai-mcp-connector\/assets\/screenshot-1.png?rev=3531806","caption":""},{"src":"https:\/\/ps.w.org\/mountdev-ai-mcp-connector\/assets\/screenshot-2.png?rev=3531806","caption":""},{"src":"https:\/\/ps.w.org\/mountdev-ai-mcp-connector\/assets\/screenshot-3.png?rev=3531806","caption":""},{"src":"https:\/\/ps.w.org\/mountdev-ai-mcp-connector\/assets\/screenshot-4.png?rev=3531806","caption":""},{"src":"https:\/\/ps.w.org\/mountdev-ai-mcp-connector\/assets\/screenshot-5.png?rev=3531806","caption":""},{"src":"https:\/\/ps.w.org\/mountdev-ai-mcp-connector\/assets\/screenshot-6.png?rev=3531806","caption":""},{"src":"https:\/\/ps.w.org\/mountdev-ai-mcp-connector\/assets\/screenshot-7.png?rev=3531806","caption":""}],"raw_content":"<!--section=description-->\n<p>Connect ChatGPT, Claude or another AI assistant to your WordPress site, then ask it to do the work you would otherwise do by hand.<\/p>\n\n<p>Connecting takes one address and a sign-in. There are no API keys to create, no client IDs to copy and nothing to paste into a configuration file. Claude and ChatGPT identify themselves automatically, using the published client metadata the Model Context Protocol defines for exactly this, and you approve the connection on your own site.<\/p>\n\n<p>Ask it to draft and publish a post, update product prices in WooCommerce, rewrite the SEO titles on a slow page, tidy your menus, or clear out spam comments. It works on your site directly, so there is no copying and pasting between a chat window and your admin screens.<\/p>\n\n<p>You decide what it may touch. Access is granted with a profile, which is a named set of tools: read only, content editing, SEO, store management, or one you build yourself. Everything the assistant does still runs through WordPress's own permissions, so it can never do more than the account it signed in as.<\/p>\n\n<h4>What you can ask for<\/h4>\n\n<ul>\n<li><strong>Content<\/strong> - draft, edit, publish and schedule posts and pages, manage categories, tags and menus<\/li>\n<li><strong>Media<\/strong> - upload images, set alt text, tidy the library<\/li>\n<li><strong>Shop<\/strong> - update products, stock, prices, variations, coupons, orders and refunds in WooCommerce<\/li>\n<li><strong>Search<\/strong> - edit titles, descriptions and schema in Rank Math or Yoast, manage redirects, check what is ranking<\/li>\n<li><strong>Pages<\/strong> - build and change Elementor layouts, global colors and typography<\/li>\n<li><strong>Forms<\/strong> - manage Contact Form 7 forms, templates and messages<\/li>\n<li><strong>Housekeeping<\/strong> - comments, users, plugins, themes and site settings<\/li>\n<\/ul>\n\n<h4>Works with the assistants people actually use<\/h4>\n\n<ul>\n<li><strong>ChatGPT<\/strong> - paste the address, sign in, done<\/li>\n<li><strong>Claude<\/strong> - paste the address, sign in, done (Claude.ai, Claude Desktop and Claude Code)<\/li>\n<li><strong>Cursor, Windsurf and other editors<\/strong> - connect with a WordPress Application Password<\/li>\n<li>Any client that speaks the Model Context Protocol<\/li>\n<\/ul>\n\n<h4>388 tools, across the plugins you already run<\/h4>\n\n<p>81 WordPress core, 78 Rank Math SEO, 74 WooCommerce, 71 Elementor (36 free and 35 Pro), 35 Jetpack, 29 Yoast SEO and 20 Contact Form 7. Tools for a plugin appear only when that plugin is active, so the list stays as short as your site is.<\/p>\n\n<p>Written for the specific plugin, not guessed at. Rank Math's focus keywords, Elementor's page structure and WooCommerce's variations each store data their own way, and each tool is built for how that plugin actually works.<\/p>\n\n<h4>Built for people who are responsible for a site<\/h4>\n\n<ul>\n<li>Nothing is sent to us or to any third party. The assistant talks to your site and nowhere else.<\/li>\n<li>Client secrets are encrypted before they are stored.<\/li>\n<li>Access tokens expire after an hour; authorization codes after ten minutes.<\/li>\n<li>Only administrators can issue credentials.<\/li>\n<li>Every action respects the signed-in user's WordPress capabilities, checked against the specific post, product or comment being touched.<\/li>\n<\/ul>\n\n<h3>Security<\/h3>\n\n<ul>\n<li><strong>OAuth 2.0 with PKCE<\/strong> - authorization requires a logged-in WordPress user and an explicit approval step<\/li>\n<li><strong>AES-256-CBC encryption<\/strong> - client secrets encrypted at rest<\/li>\n<li><strong>Token expiry<\/strong> - access tokens last an hour, refresh tokens 30 days, authorization codes ten minutes<\/li>\n<li><strong>Per-object capability checks<\/strong> - a tool checks rights over the specific object, not just a broad capability<\/li>\n<li><strong>Administrator-only credentials<\/strong> - only administrators can issue or view OAuth credentials<\/li>\n<li><strong>No privilege escalation<\/strong> - the assistant can never exceed the permissions of the account it signed in as<\/li>\n<\/ul>\n\n<h3>External Services<\/h3>\n\n<p>This plugin talks to your site and nothing else. No data is sent to Cascadia Web Services or to any third party.<\/p>\n\n<p>For editors that cannot connect to a remote MCP server themselves, the plugin includes an optional Node.js bridge script that runs on your own computer. It passes requests between the editor and your site's REST API at:<\/p>\n\n<ul>\n<li><code>https:\/\/yoursite.com\/wp-json\/mountdev-ai-mcp-connector\/v1\/messages<\/code><\/li>\n<li><code>https:\/\/yoursite.com\/wp-json\/mountdev-ai-mcp-connector\/v1\/oauth\/*<\/code><\/li>\n<\/ul>\n\n<p>It sends your WordPress username and Application Password to authenticate, along with whatever the assistant is asking for. Everything stays between your computer and your own server.<\/p>\n\n<h3>License<\/h3>\n\n<p>This plugin is licensed under the GPL v3 or later.<\/p>\n\n<p>See https:\/\/www.gnu.org\/licenses\/gpl-3.0.en.html for details.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install and activate the plugin.<\/li>\n<li>Go to <strong>Settings - MCP Connector<\/strong>.<\/li>\n<li>Copy the address shown on the page.<\/li>\n<li>In ChatGPT or Claude, add it as a custom connector and sign in when asked.<\/li>\n<li>Choose a profile, so the assistant knows what it may do.<\/li>\n<\/ol>\n\n<h4>ChatGPT and Claude<\/h4>\n\n<ol>\n<li>Copy the address from <strong>Settings - MCP Connector<\/strong>.<\/li>\n<li>In ChatGPT or Claude, open Settings, then Connectors, and add a custom connector with that address. Leave any Client ID and Secret fields empty.<\/li>\n<li>Sign in to WordPress when the window opens, and approve the request. The approval screen names the app asking and the domain that published it.<\/li>\n<li>Open the <strong>Access<\/strong> tab and choose what the assistant may do.<\/li>\n<\/ol>\n\n<p>If you prefer to issue credentials yourself, the <strong>OAuth<\/strong> tab still generates a Client ID and Secret, and connectors set up that way keep working.<\/p>\n\n<h4>Cursor, Windsurf and other editors<\/h4>\n\n<ol>\n<li>Create an Application Password under <strong>Users - Profile<\/strong>.<\/li>\n<li>Use the <strong>Client Setup<\/strong> tab to generate the configuration file for your editor.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20to%20be%20technical%20to%20use%20this%3F\"><h3>Do I need to be technical to use this?<\/h3><\/dt>\n<dd><p>No. Copy one address from the plugin into your assistant, sign in, and pick what it may do.<\/p><\/dd>\n<dt id=\"can%20it%20change%20things%20i%20did%20not%20ask%20it%20to%3F\"><h3>Can it change things I did not ask it to?<\/h3><\/dt>\n<dd><p>It can only use the tools in the profile you chose, and only within the permissions of the WordPress account that signed in. A read-only profile cannot publish, edit or delete anything.<\/p><\/dd>\n<dt id=\"is%20my%20content%20sent%20to%20anyone%3F\"><h3>Is my content sent to anyone?<\/h3><\/dt>\n<dd><p>No. Your assistant talks to your site directly. Nothing goes to us or to any third party.<\/p><\/dd>\n<dt id=\"do%20i%20need%20woocommerce%2C%20rank%20math%20or%20elementor%3F\"><h3>Do I need WooCommerce, Rank Math or Elementor?<\/h3><\/dt>\n<dd><p>No. Tools for a plugin appear only if that plugin is active. The plugin works on a plain WordPress site.<\/p><\/dd>\n<dt id=\"do%20i%20need%20an%20api%20key%20or%20a%20client%20id%3F\"><h3>Do I need an API key or a client ID?<\/h3><\/dt>\n<dd><p>No. Claude and ChatGPT identify themselves with a metadata document they publish, so you paste the address and sign in. Issuing your own credentials is still supported for clients that need it.<\/p><\/dd>\n<dt id=\"what%20is%20mcp%3F\"><h3>What is MCP?<\/h3><\/dt>\n<dd><p>The Model Context Protocol is an open standard for connecting AI assistants to outside tools and data. This plugin makes your WordPress site one of those tools.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20i%20deactivate%20the%20plugin%3F\"><h3>What happens if I deactivate the plugin?<\/h3><\/dt>\n<dd><p>The connection stops working. Nothing on your site is changed or removed.<\/p><\/dd>\n<dt id=\"can%20several%20people%20connect%3F\"><h3>Can several people connect?<\/h3><\/dt>\n<dd><p>Yes. Each person signs in as themselves, and what they can do follows their own WordPress role.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.6.9<\/h4>\n\n<ul>\n<li>Changed: Deleting the plugin now removes everything it stored: profiles, settings, OAuth credentials, tokens and the key they were encrypted with. Until now these were left behind, so a site that had removed the plugin still held credentials that could authorize an assistant against it. Deactivating changes nothing; only deleting does this, and reconnecting after a delete means setting the connection up again<\/li>\n<li>Note: Your posts, products, media and anything an assistant created are your site's own content and are never touched<\/li>\n<\/ul>\n\n<h4>1.6.8<\/h4>\n\n<ul>\n<li>Fixed: A GET request to the MCP endpoint returned the authorization server metadata with HTTP 200 instead of the 401 challenge. Clients following the MCP authorization spec, ChatGPT among them, probe the endpoint first and expect that challenge to find the protected resource metadata. Reaching the authorization metadata this way left ChatGPT reporting that PKCE support was not advertised, even though it was. Reported on parsiagent.ir against 1.6.7<\/li>\n<li>Added: Claude and ChatGPT can now connect with your site address alone. They identify themselves with a published metadata document (CIMD, per MCP SEP-991), so there are no credentials to generate first. Connections using generated credentials are unaffected<\/li>\n<li>Added: The approval screen names the app asking for access, says which domain published it, and says so plainly when the app is running on your own computer<\/li>\n<li>Changed: The settings screen uses WordPress's own layout and styling<\/li>\n<li>Changed: Promotional banners and the advertising sidebar removed<\/li>\n<li>Changed: The page opens on Quick Start instead of the FAQ, and the Profiles tab is now called Access<\/li>\n<li>Fixed: The tool count said 389; there are 388 (81 WordPress core, not 82)<\/li>\n<li>Changed: Readme rewritten in plain language<\/li>\n<li>Note: Existing connections keep working and do not need setting up again<\/li>\n<\/ul>\n\n<h4>1.6.7<\/h4>\n\n<ul>\n<li>Fixed: ChatGPT connectors failed with \"OAuth authorization server metadata must advertise PKCE support with code_challenge_methods_supported containing S256\". The plugin did not implement RFC 9728 Protected Resource Metadata, and the 401 <code>WWW-Authenticate<\/code> header's <code>resource_metadata<\/code> pointed at the authorization server metadata instead. It is now served at <code>\/.well-known\/oauth-protected-resource\/wp-json\/mountdev-ai-mcp-connector\/v1\/messages<\/code> (and <code>\/.well-known\/oauth-protected-resource<\/code>), and <code>authorization_servers<\/code> leads clients to the existing metadata<\/li>\n<li>Fixed: 401 responses for an expired or invalid access token now carry the <code>WWW-Authenticate<\/code> challenge too<\/li>\n<li>Fixed: The token endpoint now accepts client credentials sent with HTTP Basic authentication (<code>client_secret_basic<\/code>), which the metadata already advertised<\/li>\n<li>Security: A <code>client_secret<\/code> sent with a PKCE token or refresh request is now verified. Previously a wrong secret was ignored when PKCE succeeded<\/li>\n<li>Note: If a client is configured with a Client Secret, it must be the current one shown in the OAuth settings. Clients that send no secret are unaffected<\/li>\n<\/ul>\n\n<h4>1.6.6<\/h4>\n\n<ul>\n<li>Security: Fixed an authenticated broken access control vulnerability affecting every tool that takes an object ID. Only the single broad capability on each tool definition (<code>read<\/code>, <code>edit_posts<\/code>, <code>delete_posts<\/code>) was checked, never the caller's rights over the specific object, so a low-privileged authenticated user could act on content belonging to anyone. Reported by Ananda Dhakal (Patchstack)<\/li>\n<li>Security: <code>get_post<\/code>, <code>get_post_meta<\/code> and <code>get_post_revisions<\/code> now run WordPress's <code>read_post<\/code> capability for the requested object \u2014 under the default read-only profile a Subscriber could previously retrieve Administrator-owned private pages and drafts by ID<\/li>\n<li>Security: <code>list_posts<\/code>, <code>get_posts<\/code>, <code>get_pages<\/code>, <code>search_posts<\/code> and <code>search<\/code> reduce the caller-supplied <code>status<\/code> to the statuses that user may actually see, and scope the query to their own authorship where they may only see their own \u2014 previously <code>status=draft<\/code> returned everyone's drafts<\/li>\n<li>Security: <code>create_post<\/code> and <code>create_page<\/code> authorize the requested status, post type and author \u2014 publishing (and scheduling, and private status) now requires <code>publish_posts<\/code>, so a Contributor can no longer publish, and internal post types are rejected<\/li>\n<li>Security: <code>update_post<\/code>, <code>update_page<\/code>, <code>delete_post<\/code> and <code>delete_page<\/code> require <code>edit_post<\/code> \/ <code>delete_post<\/code> for the target object, plus a separate check on the requested transition, so another user's content can no longer be rewritten, unpublished or permanently deleted<\/li>\n<li>Security: <code>update_post_meta<\/code> and <code>delete_post_meta<\/code> use core's <code>edit_post_meta<\/code> \/ <code>delete_post_meta<\/code> capabilities and reject protected keys; <code>get_post_meta<\/code> hides protected keys from users who cannot edit the post<\/li>\n<li>Security: Media tools authorize the attachment itself, comment tools authorize the specific comment, and <code>assign_terms<\/code> requires edit rights on the post plus <code>assign_terms<\/code> on the taxonomy<\/li>\n<li>Security: <code>create_comment<\/code> requires being able to read the post and finding comments open on it, and no longer bypasses moderation \u2014 comments from users without <code>moderate_comments<\/code> are queued rather than published immediately<\/li>\n<li>Note: No configuration change is required and no profile is modified. Administrator and Editor behaviour is unchanged<\/li>\n<\/ul>\n\n<h4>1.6.5<\/h4>\n\n<ul>\n<li>Added: The MCP Router settings tab is now visible, exposing the first-party MountDev MCP Router configuration UI<\/li>\n<li>Changed: The MountDev MCP Router callback hosts are now allowed OAuth redirect hosts so the router can complete the authorization flow<\/li>\n<\/ul>\n\n<h4>1.6.4<\/h4>\n\n<ul>\n<li>Security: Fixed a critical OAuth authorization bypass (CVE-2026-15015) \u2014 <code>\/oauth\/authorize<\/code> auto-selected the site's first administrator and issued an access token to any unauthenticated caller presenting a valid <code>client_id<\/code>. It now requires a logged-in WordPress user and explicit Approve\/Deny consent, and binds the token to the user who approved rather than an arbitrary admin. This affected all releases up to and including 1.6.3; see the retraction under 1.6.1 below<\/li>\n<li>Security: All existing OAuth authorization codes, access tokens and refresh tokens are revoked on upgrade, because any of them may have been obtained through the bypass \u2014 every connected client must authorize again<\/li>\n<li>Security: <code>redirect_uri<\/code> is now validated against an allowlist before a code is issued and again at token exchange, matching on parsed host rather than string prefix; loopback callbacks are allowed per RFC 8252<\/li>\n<li>Security: PKCE is now mandatory and S256-only; <code>plain<\/code> is rejected at request time, in <code>verify_pkce()<\/code>, and no longer advertised in any metadata document<\/li>\n<li>Security: Authorization codes are bound to the <code>client_id<\/code> and <code>redirect_uri<\/code> they were issued for and are invalidated on any failed redemption; the refresh grant now validates client identity<\/li>\n<li>Security: Clients that self-registered via Dynamic Client Registration before 1.6.3 were still accepted at runtime; they are no longer honoured and the records are deleted<\/li>\n<li>Fixed: The authorization endpoint is now served outside the REST API. Cookie authentication does not work for REST requests without an <code>X-WP-Nonce<\/code>, which a browser navigation from an OAuth client never carries \u2014 this made the login check always fail and is why the fix written for 1.6.1 was reverted<\/li>\n<li>Fixed: Hosts and plugins that force every login to their own page can no longer strand the authorization flow<\/li>\n<\/ul>\n\n<h4>1.6.3<\/h4>\n\n<ul>\n<li>Security: Removed OAuth Dynamic Client Registration (<code>\/mcp-register<\/code>, <code>\/register<\/code>, <code>\/oauth\/register<\/code>) \u2014 clients can no longer self-provision a <code>client_id<\/code>; connect using admin-issued OAuth credentials from the plugin's admin panel instead<\/li>\n<\/ul>\n\n<h4>1.6.2<\/h4>\n\n<ul>\n<li>Added: 7 new WordPress Core menu tools - update_nav_menu, delete_nav_menu, add_menu_item, update_menu_item, delete_menu_item, get_menu_locations, set_menu_location<\/li>\n<li>Fixed: Navigation menus could previously only be listed and created, not renamed, deleted, populated with items, or assigned to a theme location<\/li>\n<li>Changed: Tool count increased from 382 to 389 total tools (75 to 82 WordPress core)<\/li>\n<\/ul>\n\n<h4>1.6.1<\/h4>\n\n<ul>\n<li>RETRACTION: The security entries originally published for this release were incorrect. The commit implementing them broke the OAuth flow for Claude and ChatGPT and was reverted before 1.6.1 shipped, but the changelog was not corrected at the time. CVE-2026-15015 remained exploitable in 1.6.1, 1.6.2 and 1.6.3, and is fixed in 1.6.4. Dynamic Client Registration removal was part of the same reverted commit and did not ship until 1.6.3. The withdrawn entries were: an OAuth authorization bypass fix requiring login and consent, <code>redirect_uri<\/code> allowlist validation, PKCE S256 enforcement at request time, a Claude.ai redirect URI allowlist entry, and login-redirect hijack protection<\/li>\n<\/ul>\n\n<h4>1.6.0<\/h4>\n\n<ul>\n<li>Added: 35 Jetpack tools for module control, stats &amp; analytics, related posts, sharing, subscriptions, SEO, publicize connections, and protect settings (requires Jetpack plugin)<\/li>\n<li>Added: 5 new Jetpack profiles - Read Only, Analyst, Site Manager, Content Manager, and Full Access<\/li>\n<li>Added: MCP Server URL now shown in the OAuth credentials generated modal for quick copying<\/li>\n<li>Changed: Plugin renamed to \"MountDev AI MCP Connector for WordPress\"<\/li>\n<li>Changed: Tool count increased from 347 to 382 total tools<\/li>\n<li>Fixed: OAuth token exchange failure for Claude Desktop and claude.ai<\/li>\n<li>Fixed: OAuth <code>\/authorize<\/code> and <code>\/token<\/code> fallback handling on sites that block <code>.well-known<\/code> requests<\/li>\n<\/ul>\n\n<h4>1.5.2<\/h4>\n\n<ul>\n<li>Fixed: Button size adjusted to fit profile cards correctly<\/li>\n<li>Fixed: Icon color not visible in create profile button<\/li>\n<li>Fixed: Removed icons from profile action buttons to resolve alignment issue<\/li>\n<li>Added: Settings link on the plugin page for quicker access<\/li>\n<li>Changed: Marked tested up to WordPress 7.0<\/li>\n<\/ul>\n\n<h4>1.5.1<\/h4>\n\n<ul>\n<li>Added: 35 Elementor Pro tools for form submissions, theme builder templates, popups, global widgets, dynamic tags, loop templates, notes, custom fonts\/icons, WooCommerce settings, element permissions, and role manager (requires Elementor Pro)<\/li>\n<li>Added: 2 new predefined profiles for Elementor Pro (elementor_pro_designer, elementor_pro_full_access)<\/li>\n<li>Improved: Profile manager category filter for easier navigation in admin UI<\/li>\n<li>Improved: OAuth Claude Desktop setup instructions updated with clearer guidance<\/li>\n<li>Changed: Tool count increased from 312 to 347 total tools<\/li>\n<\/ul>\n\n<h4>1.5.0<\/h4>\n\n<ul>\n<li>Added: 36 Elementor FREE tools for complete page builder management (list\/get\/create\/delete pages, read\/write elements tree, global colors, global fonts, site settings, template library, plugin settings, experiments, CSS regeneration)<\/li>\n<li>Added: 3 new predefined profiles (elementor_read_only, elementor_designer, elementor_full_access)<\/li>\n<li>Added: Elementor plugin banner and tool grouping in admin UI<\/li>\n<li>Changed: Tool count increased from 276 to 312 total tools<\/li>\n<\/ul>\n\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>Added: 20 Contact Form 7 tools for complete form management (list, get, create, update, delete, duplicate, mail templates, messages, additional settings, plugin settings, integrations)<\/li>\n<li>Added: 3 new predefined profiles (cf7_read_only, cf7_form_manager, cf7_full_access)<\/li>\n<li>Added: Contact Form 7 plugin banner and profile category in admin UI<\/li>\n<li>Changed: Tool count increased from 256 to 276 total tools<\/li>\n<\/ul>\n\n<h4>1.3.2<\/h4>\n\n<ul>\n<li>Fixed: RankMath per-post robots meta (noindex, nofollow, noarchive, noimageindex, nosnippet) now readable and writable via rankmath_get\/update_post_meta<\/li>\n<li>Fixed: RankMath schema tools rewritten to use modern rank_math_schema_* meta format (was using deprecated rank_math_rich_snippet keys)<\/li>\n<li>Fixed: rankmath_update_schema, rankmath_get_post_schema, rankmath_add_faq_schema, rankmath_add_howto_schema now work correctly with Rank Math 1.0.42+<\/li>\n<\/ul>\n\n<h4>1.3.1<\/h4>\n\n<ul>\n<li>Added: 11 new Yoast SEO tools (robot directives, breadcrumb title, term SEO metadata, global settings, keyword usage, post type settings, update redirect, inclusive language score)<\/li>\n<li>Fixed: Yoast SEO Premium tools were unreachable due to an early return in get_tools()<\/li>\n<li>Fixed: RankMath create_redirect now correctly uses the sources column; url_to\/destination values were swapped<\/li>\n<li>Changed: Tool count increased from 245 to 256 total tools<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>Added: 78 Rank Math SEO tools for comprehensive SEO management<\/li>\n<li>Added: 18 core read tools (post meta, social meta, canonical, content analysis, keyword analysis, schema, sitemap settings)<\/li>\n<li>Added: 16 core write tools (update post meta, social meta, schema, canonical, FAQ\/HowTo schema blocks, global\/sitemap settings)<\/li>\n<li>Added: 6 redirect and 404 monitor tools (list\/create\/bulk-delete\/export redirects, 404 logs, 404 summary)<\/li>\n<li>Added: 6 analytics tools (site analytics, Search Console data, winning\/losing posts, Content AI score)<\/li>\n<li>Added: 32 Rank Math Pro tools (Schema Templates, Link Genius, Keyword Tracking, Multi-Location, News\/Video Sitemaps, Image SEO, Email Reports)<\/li>\n<li>Added: 3 new predefined profiles (rankmath_read_only, rankmath_content_optimizer, rankmath_full_access)<\/li>\n<li>Added: Pro badge detection in Profile Manager for profiles requiring Rank Math Pro<\/li>\n<li>Fixed: Page parent parameter now correctly sets post hierarchy when creating\/updating pages<\/li>\n<li>Fixed: Reading Settings options (homepage display, feed settings) added to site tools whitelist<\/li>\n<li>Fixed: Claude Desktop OAuth setup instructions added to client setup page<\/li>\n<li>Changed: Tool count increased from 167 to 245 total tools<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Added: 18 Yoast SEO tools for comprehensive SEO management<\/li>\n<li>Added: 3 new predefined profiles (yoast_read_only, yoast_content_optimizer, yoast_full_access)<\/li>\n<li>Added: Yoast SEO Premium support with redirect management and multiple keywords<\/li>\n<li>Added: Content analysis, readability scoring, and keyword optimization tools<\/li>\n<li>Added: Schema markup management (page types and article types)<\/li>\n<li>Added: Social meta management (Open Graph and Twitter Card)<\/li>\n<li>Changed: Tool count increased from 149 to 167 total tools<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Changed: Updated readme description for better clarity<\/li>\n<li>Fixed: WooCommerce default profiles now properly hidden when WooCommerce plugin is deactivated<\/li>\n<li>Fixed: Removed WooCommerce badge from FAQ section when WooCommerce is not active<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Added: 74 WooCommerce tools across 3 new tool classes<\/li>\n<li>Added: 4 new predefined profiles (woo_read_only, woo_store_manager, woo_full_access, complete_site)<\/li>\n<li>Added: WooCommerce Brands extension support with 5 brand management tools<\/li>\n<li>Added: Global product attributes management with 8 attribute tools<\/li>\n<li>Added: Enhanced Profile Manager UI with WooCommerce branding and search\/filter<\/li>\n<li>Added: Advanced product features (Global Unique ID, sold individually, shipping dimensions, linked products)<\/li>\n<li>Added: Comprehensive coupon management with usage restrictions and limits<\/li>\n<li>Changed: Profile Manager UI now separates WordPress and WooCommerce tools<\/li>\n<li>Changed: Tool categories expanded from 10 to 28 categories<\/li>\n<li>Changed: Tool count increased from 75 to 149 total tools<\/li>\n<li>Technical: Conditional WooCommerce tool registration (only when WooCommerce is active)<\/li>\n<li>Technical: 3 new tool classes (Woo_Product_Tools, Woo_Order_Tools, Woo_Store_Tools)<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release<\/li>\n<li>MCP Server Implementation with JSON-RPC 2.0 endpoint<\/li>\n<li>OAuth 2.0 support for ChatGPT<\/li>\n<li>WordPress Application Passwords for Claude Desktop, Cursor, Windsurf<\/li>\n<li>75 WordPress core tools across 10 categories<\/li>\n<li>Profile-based access control with 3 predefined profiles<\/li>\n<\/ul>","raw_excerpt":"Connect ChatGPT or Claude to WordPress with one address, no API keys. Your assistant can write posts, update products and fix SEO, within limits you s &hellip;","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/tw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/285474","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/tw.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/tw.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=285474"}],"author":[{"embeddable":true,"href":"https:\/\/tw.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/cascadiawebservices"}],"wp:attachment":[{"href":"https:\/\/tw.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=285474"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/tw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=285474"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/tw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=285474"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/tw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=285474"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/tw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=285474"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/tw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=285474"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}