Insecure Direct Object Reference in AI Engine for WordPress by WordPress
CVE-2026-89141
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 September 2026
What is CVE-2026-89141?
The AI Engine plugin for WordPress exposes an Insecure Direct Object Reference vulnerability that allows authenticated attackers with subscriber-level access and above to access private audio attachments of other users by exploiting the 'mediaId' parameter. This flaw arises from a lack of validation on user-controlled keys, enabling unauthorized retrieval of transcribed contents. The vulnerability is only exploitable when the Public API module is enabled; if disabled, the corresponding REST route is not available, thus preventing access.
Affected Version(s)
AI Engine β The Chatbot, AI Framework & MCP for WordPress 0 <= 3.7.7