Stored Cross-Site Scripting in AI Engine Plugin for WordPress
CVE-2026-96561
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-96561?
The AI Engine plugin for WordPress is susceptible to stored cross-site scripting due to insufficient input sanitization and output escaping. An unauthenticated attacker can exploit vulnerabilities in key functionalities within the plugin, such as the /mwai-ui/v1/chats/submit REST endpoint, PHP error-log parser, and the advisor dashboard widget. By injecting crafted inputs, attackers can manipulate error logs and stored JSON data, leading to execution of arbitrary web scripts within the WordPress dashboard. An upgrade to the latest version is necessary to mitigate these risks and protect website integrity.
Affected Version(s)
AI Engine β The Chatbot, AI Framework & MCP for WordPress 0 <= 3.8.0