Cross-Site Request Forgery Vulnerability in AI Engine Plugin for WordPress
CVE-2026-15988
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 August 2026
What is CVE-2026-15988?
The AI Engine β Chatbot, AI Framework & MCP for WordPress is susceptible to Cross-Site Request Forgery due to inadequate nonce validation in the reauth_for_authorize function. This vulnerability enables unauthenticated attackers to bypass authentication, potentially creating new administrator accounts by manipulating site administrators into executing specific actions, such as clicking malicious links. The flaw allows attackers to exploit WordPress's method-override capabilities, transforming a simple GET request into an authenticated POST request to the REST users endpoint, without requiring a pre-existing account.
Affected Version(s)
AI Engine β The Chatbot, AI Framework & MCP for WordPress 0 <= 3.6.5