Insecure Direct Object Reference in AI Engine for WordPress by WordPress
CVE-2026-89141

6.5MEDIUM

What is CVE-2026-89141?

The AI Engine plugin for WordPress exposes an Insecure Direct Object Reference vulnerability that allows authenticated attackers with subscriber-level access and above to access private audio attachments of other users by exploiting the 'mediaId' parameter. This flaw arises from a lack of validation on user-controlled keys, enabling unauthorized retrieval of transcribed contents. The vulnerability is only exploitable when the Public API module is enabled; if disabled, the corresponding REST route is not available, thus preventing access.

Affected Version(s)

AI Engine – The Chatbot, AI Framework & MCP for WordPress 0 <= 3.7.7

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chi Trung Huynh
.