#37390·elementor

Elementor MCP: tools/list, prompts/list, resources/list return -32603 after successful initialize

Author: raggiobrcCreated Sep 22, 2026Updated Sep 22, 2026
Labelsstatus/awaiting_triage

Description

Environment:

  • Elementor MCP Composer: v1.0.13
  • MCP server: "Elementor MCP" v1.0.0
  • WordPress: 7.1.1
  • Client: fastmcp-remote (FastMCP 4.0.5) via Claude Desktop, and raw curl
  • Auth: Basic Auth with a valid WordPress Application Password

Summary: Right after a successful initialize call (HTTP 200, valid Mcp-Session-Id returned), any MCP client that follows the normal handshake — send tools/list, prompts/list, resources/list right after notifications/initialized — gets error(code=-32603) ("Internal error") on all three, even though the session ID and auth are valid.

A single, isolated tools/list call (via curl, made after the concurrent batch had already failed) with the same valid session ID succeeds and returns the full tool list (55+ tools). This suggests the internal error may be caused by concurrent/near-simultaneous requests sharing the same Mcp-Session-Id, rather than a problem with the session ID or auth themselves.

Steps to reproduce:

  1. Configure an MCP client (e.g. Claude Desktop with fastmcp-remote) against https:///wp-json/elementor/mcp/ using Basic Auth with a valid WordPress Application Password.
  2. Let the client run its normal handshake: initialize → notifications/initialized → tools/list + prompts/list + resources/list (most clients fire these three in parallel).
  3. Observe: initialize succeeds, but the three list calls all return error -32603.
  4. As a control: run tools/list alone, sequentially, well after the above sequence, with the same session ID. It succeeds.

Separate issue observed on the same plugin screen (Settings → MCP → Claude Desktop tab): The "Generate and copy the configuration" button displays a plaintext Application Password and a matching config block, but does NOT appear to actually create that Application Password in WordPress — the displayed credential fails with incorrect_password on every request. Generating the Application Password manually via WP Admin → Users → Profile → Application Passwords works correctly. This may be worth checking separately, as it silently breaks the one-click setup flow this screen offers.

Happy to provide full request/response logs (with credentials redacted) if useful.

Steps to reproduce

Steps to reproduce:

  1. Configure an MCP client (e.g. Claude Desktop with fastmcp-remote) against https:///wp-json/elementor/mcp/ using Basic Auth with a valid WordPress Application Password.
  2. Let the client run its normal handshake: initialize → notifications/initialized → tools/list + prompts/list + resources/list (most clients fire these three in parallel).
  3. Observe: initialize succeeds, but the three list calls all return error -32603.
  4. As a control: run tools/list alone, sequentially, well after the above sequence, with the same session ID. It succeeds.

Expected behavior

All three calls (tools/list, prompts/list, resources/list) should return their respective results (HTTP 200 with the requested data), the same way tools/list does when called in isolation with a valid session ID.

Since initialize succeeds and returns a valid Mcp-Session-Id, and a standalone tools/list call with that same session ID works correctly, the three list calls should also succeed when fired together right after the handshake — this is the normal behavior any MCP client relies on, since most clients (including fastmcp-remote) request tools/list, prompts/list and resources/list together as part of connecting.

Elementor System Info

txt
== Server Environment ==
	Operating System: Linux
	Software: Apache
	MySQL version: (Ubuntu) v8.0.46
	PHP Version: 8.4.25
	PHP Memory Limit: 1024M
	PHP Max Input Vars: 7000
	PHP Max Post Size: 64M
	GD Installed: Yes
	ZIP Installed: Yes
	Write Permissions: All right
	Elementor Library: Connected

== WordPress Environment ==
	Version: 7.1.2
	Site URL: https://labicicleta.com.uy
	Home URL: https://labicicleta.com.uy
	WP Multisite: No
	Max Upload Size: 64 MB
	Memory limit: 512M
	Max Memory limit: 512M
	Permalink Structure: /%postname%/
	Language: es_UY
	Timezone: America/Montevideo
	Admin Email: [email protected]
	Debug Mode: Inactive

== Theme ==
	Name: Hello Elementor
	Version: 3.5.1
	Author: Elementor Team
	Child Theme: No

== User ==
	Role: administrator
	WP Profile lang: es-UY
	User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0

== Active Plugins ==
	Advanced Custom Fields
		Version: 6.8.10
		Author: WP Engine

	Akismet Anti-spam: Spam Protection
		Version: 5.7.2
		Author: Automattic - Anti-spam Team

	Angie
		Version: 1.1.16
		Author: Elementor.com

	Bookings and Appointments For WooCommerce Premium
		Version: 6.0.1
		Author: PluginHive

	BulletProof Security
		Version: 7.2
		Author: AITpro Website Security

	Classic Editor
		Version: 1.7.0
		Author: WordPress Contributors

	Contact Form 7
		Version: 6.1.7
		Author: Rock Lobster Inc.

	Custom Post Type UI
		Version: 1.19.3
		Author: WebDevStudios

	Elementor
		Version: 4.3.0-beta3
		Author: Elementor.com

	Google Analytics for WordPress by MonsterInsights
		Version: 11.3.0
		Author: MonsterInsights

	Headers Security Advanced & HSTS WP
		Version: 5.3.5
		Author:  Andrea Ferro

	Login Logo
		Version: 0.10.3
		Author: Mark Jaquith

	PH WooCommerce Product Addons
		Version: 1.4.0
		Author: PluginHive

	PRO Elements
		Version: 4.2.3
		Author: PROElements.org

	Stock de Vinos
		Version: 1.5.0
		Author: Desarrollo personalizado

	WooCommerce
		Version: 11.1.1
		Author: Automattic

	Wordfence Security
		Version: 9.0.1
		Author: Wordfence

	Yoast Duplicate Post
		Version: 4.7
		Author: Enrico Battocchi & Team Yoast


== Must-Use Plugins ==
	BPS MU Tools
		Version: 9.0
		Author: AITpro


== Features ==
	Custom Fonts: 0
	Custom Icons: 0

== Integrations ==
	
	woocommerce: Active


== Experimentos de Elementor ==
	Fuentes de iconos integradas: Activo por defecto
	Puntos de ruptura personalizados adicionales: Activo por defecto
	Contenedor: Activo
	Optimized Markup: Activo por defecto
	Optimized CSS Files: Inactivo por defecto
	Default to New Theme Builder: Activo
	Header & Footer: Activo por defecto
	Elementos anidados: Activo por defecto
	Panel de páginas: Inactivo por defecto
	Atomic Widgets: Activo
	Lista: Inactivo por defecto
	Icon Button: Inactivo por defecto
	Acordeón: Inactivo por defecto
	SVG Library: Inactivo por defecto
	Launchpad Checklist: Inactivo por defecto
	Page Audit: Inactivo por defecto
	Editor V4: Activo
	Component Variants: Inactivo por defecto
	Angie in editor panels: Inactivo por defecto
	Generate website markdown: Inactivo por defecto
	Agents llms.txt: Inactivo por defecto
	Dynamic Assets Management: Inactivo por defecto
	Import/Export Customization: Activo por defecto
	Elementor Editor Events: Activo por defecto
	Atomic Form: Activo por defecto
	Loop: Activo por defecto
	Menu: Activo
	Size Variables: Activo por defecto
	Pro Interactions: Activo por defecto
	In-Editor Feedback: Inactivo por defecto


== Registro ==
	
Log: showing 20 of 372026-08-25 08:45:26 [info] Elementor data updater process has been queued. [array (
  'plugin' => 'PRO Elements',
  'from' => '4.1.0',
  'to' => '4.2.2',
)]
2026-08-25 08:45:59 [info] elementor-pro::elementor_pro_updater Started 
2026-08-25 08:45:59 [info] PRO Elements/Upgrades - _on_each_version Start  
2026-08-25 08:45:59 [info] PRO Elements/Upgrades - _on_each_version Finished 
2026-08-25 08:45:59 [info] Elementor data updater process has been completed. [array (
  'plugin' => 'PRO Elements',
  'from' => '4.1.0',
  'to' => '4.2.2',
)]
2026-08-31 20:48:37 [info] elementor::elementor_updater Started 
2026-08-31 20:48:37 [info] Elementor/Upgrades - _on_each_version Start  
2026-08-31 20:48:37 [info] Elementor/Upgrades - _on_each_version Finished 
2026-08-31 20:48:37 [info] Elementor data updater process has been completed. [array (
  'plugin' => 'Elementor',
  'from' => '4.2.3',
  'to' => '4.2.4',
)]
2026-09-15 16:50:42 [info] Elementor data updater process has been queued. [array (
  'plugin' => 'PRO Elements',
  'from' => '4.2.2',
  'to' => '4.2.3',
)]
2026-09-15 16:50:42 [info] elementor-pro::elementor_pro_updater Started 
2026-09-15 16:50:42 [info] PRO Elements/Upgrades - _on_each_version Start  
2026-09-15 16:50:42 [info] PRO Elements/Upgrades - _on_each_version Finished 
2026-09-15 16:50:42 [info] Elementor data updater process has been completed. [array (
  'plugin' => 'PRO Elements',
  'from' => '4.2.2',
  'to' => '4.2.3',
)]
2026-09-15 16:50:43 [info] Elementor data updater process has been queued. [array (
  'plugin' => 'PRO Elements',
  'from' => '4.2.2',
  'to' => '4.2.3',
)]
2026-09-20 19:13:34 [info] Elementor data updater process has been queued. [array (
  'plugin' => 'Elementor',
  'from' => '4.2.4',
  'to' => '4.3.0-beta3',
)]
2026-09-20 19:13:46 [info] elementor::elementor_updater Started 
2026-09-20 19:13:46 [info] Elementor/Upgrades - _on_each_version Start  
2026-09-20 19:13:46 [info] Elementor/Upgrades - _on_each_version Finished 
2026-09-20 19:13:46 [info] Elementor data updater process has been completed. [array (
  'plugin' => 'Elementor',
  'from' => '4.2.4',
  'to' => '4.3.0-beta3',
)]

PHP: showing 2 of 2PHP: 2026-09-16 18:38:58 [error X 1][/home/www/vservers/labicicleta.com.uy/wp-content/plugins/elementor/modules/ai/module.php::351] Uncaught Error: Call to a member function get_gallery_image_ids() on false in /home/www/vservers/labicicleta.com.uy/wp-content/plugins/elementor/modules/ai/module.php:351
Stack trace:
#0 /home/www/vservers/labicicleta.com.uy/wp-includes/class-wp-hook.php(353): Elementor\Modules\Ai\Module->get_product_images_ajax()
#1 /home/www/vservers/labicicleta.com.uy/wp-includes/class-wp-hook.php(377): WP_Hook->apply_filters()
#2 /home/www/vservers/labicicleta.com.uy/wp-includes/plugin.php(523): WP_Hook->do_action()
#3 /home/www/vservers/labicicleta.com.uy/wp-admin/admin-ajax.php(192): do_action()
#4 {main}
  thrown [array (
  'trace' => '
#0: Elementor\Core\Logger\Manager -> shutdown()
',
)]
PHP: 2026-09-20 19:13:46 [notice X 8872][/home/www/vservers/labicicleta.com.uy/wp-content/plugins/elementor/modules/global-classes/atomic-global-styles.php::410] Elementor\Modules\GlobalClasses\Atomic_Global_Styles::get_cache_root_key(): Implicitly marking parameter $key as nullable is deprecated, the explicit nullable type must be used instead [array (
  'trace' => '
#0: Elementor\Core\Logger\Manager -> shutdown()
',
)]

JS: showing 3 of 3JS: 2026-09-19 02:55:45 [error X 1][https://labicicleta.com.uy/wp-content/plugins/elementor/assets/js/editor.min.js?ver=4.2.4:2:249647] this.ui.input.val is not a function 
JS: 2026-09-19 02:58:51 [error X 3][https://labicicleta.com.uy/wp-content/plugins/elementor/assets/js/editor.min.js?ver=4.2.4:2:1230109] Failed to read a named property 'elementorFrontend' from 'Window': Blocked a frame with origin "https://labicicleta.com.uy" from accessing a cross-origin frame. 
JS: 2026-09-20 21:50:37 [error X 11][https://labicicleta.com.uy/wp-content/plugins/elementor/assets/js/admin.min.js?ver=4.2.4:2:42363] r.startsWith is not a function 



== Elementor - Compatibility Tag ==
	
	PRO Elements: Incompatible

== PRO Elements - Compatibility Tag ==

Agreement

  • I confirm I have read and followed all the guidelines and instructions outlined in the Elementor Bug Report form.
  • I agree that my issue may be closed without further action if it doesn't meet all the requirements outlined in the Elementor Bug Report form.