The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only features, relying instead on a token it hands out to anonymous visitors, allowing unauthenticated attackers to run AI queries of their own choosing against the site owner's configured provider account.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-26 06:16
Updated : 2026-08-26 16:30
NVD link : CVE-2026-75798
Mitre link : CVE-2026-75798
CVE.ORG link : CVE-2026-75798
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
