Stored Cross-Site Scripting in AI Engine Plugin for WordPress
CVE-2026-96561

7.2HIGH

What is CVE-2026-96561?

The AI Engine plugin for WordPress is susceptible to stored cross-site scripting due to insufficient input sanitization and output escaping. An unauthenticated attacker can exploit vulnerabilities in key functionalities within the plugin, such as the /mwai-ui/v1/chats/submit REST endpoint, PHP error-log parser, and the advisor dashboard widget. By injecting crafted inputs, attackers can manipulate error logs and stored JSON data, leading to execution of arbitrary web scripts within the WordPress dashboard. An upgrade to the latest version is necessary to mitigate these risks and protect website integrity.

Affected Version(s)

AI Engine – The Chatbot, AI Framework & MCP for WordPress 0 <= 3.8.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

whale120
.