Privilege Escalation Vulnerability in AI Engine Plugin for WordPress
CVE-2026-8719
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 May 2026
What is CVE-2026-8719?
The AI Engine plugin, designed for WordPress, is susceptible to a privilege escalation vulnerability that arises from inadequate enforcement of WordPress capabilities. Specifically, in version 3.4.9, a flaw exists in the MCP OAuth bearer-token authorization process. This vulnerability permits any valid OAuth token to access MCP features without appropriate checks on administrator privileges. As a result, an authenticated user with Subscriber or higher roles can exploit this weakness to gain unauthorized access to administrative tools, significantly elevating their permissions.
Affected Version(s)
AI Engine β The Chatbot, AI Framework & MCP for WordPress 3.4.9