CVE-2026-16954
AI Engine < 3.6.4 - Editor+ Sensitive Information Disclosure of API Key and Bearer Tokens
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admin page's inline script data, allowing users with the Editor role to read the site's stored third-party API key and authentication tokens in cleartext, despite those secrets being restricted to administrators everywhere else.
| Vendor | unknown |
| Product | ai engine |
| Published | Aug 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown ai engine
Be the first to know when new unknown vulnerabilities affecting unknown ai engine are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / AI Engine
0 < 3.6.4
References
Credits
Revanth Hari Narayana Matte WPScan