WP Vulnerability WatchVulnerability data as of September 15, 2026

Vulnerability alerts / September 14, 2026

Vulnerability in AI Engine – The Chatbot, AI Framework & MCP for WordPress — CVE-2026-89141

MediumSeverity
CVSS 6.5
Estimated exploit probability
EPSS
100,000+ sitesInstalls
3.7.8Fixed in

What to do now

Update AI Engine – The Chatbot, AI Framework & MCP for WordPress to 3.7.8 or later.

Affected versions

  • Everything up to and including 3.7.7

Affected: AI Engine – The Chatbot, AI Framework & MCP for WordPress (plugin, ai-engine)

Check: The plugin on wordpress.org / Our record for AI Engine – The Chatbot, AI Framework & MCP for WordPress

What the vulnerability is

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via the 'mediaId' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to access and retrieve the transcribed contents of private audio attachments belonging to other users, including Administrators, via a supplied attachment ID. This vulnerability requires the Public API module to be enabled in the plugin settings; when disabled, the REST route is absent and the endpoint returns HTTP 404.

This description is reproduced verbatim from the public vulnerability record.

Sources

Part of this record comes from Wordfence Intelligence. Original: https://www.wordfence.com/threat-intel/vulnerabilities/id/2cb2ad5d-aa92-4186-aaae-45dde4a52f30
Copyright 2012-2026 Defiant Inc. / Full license text

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts