Privilege Escalation Vulnerability in AI Engine Plugin for WordPress
CVE-2026-8719

8.8HIGH

What is CVE-2026-8719?

The AI Engine plugin, designed for WordPress, is susceptible to a privilege escalation vulnerability that arises from inadequate enforcement of WordPress capabilities. Specifically, in version 3.4.9, a flaw exists in the MCP OAuth bearer-token authorization process. This vulnerability permits any valid OAuth token to access MCP features without appropriate checks on administrator privileges. As a result, an authenticated user with Subscriber or higher roles can exploit this weakness to gain unauthorized access to administrative tools, significantly elevating their permissions.

Affected Version(s)

AI Engine – The Chatbot, AI Framework & MCP for WordPress 3.4.9

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo
.