๐Ÿ” CVE Alert

CVE-2026-16954

UNKNOWN 0.0

AI Engine < 3.6.4 - Editor+ Sensitive Information Disclosure of API Key and Bearer Tokens

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admin page's inline script data, allowing users with the Editor role to read the site's stored third-party API key and authentication tokens in cleartext, despite those secrets being restricted to administrators everywhere else.

Vendor unknown
Product ai engine
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for unknown ai engine

Be the first to know when new unknown vulnerabilities affecting unknown ai engine are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / AI Engine
0 < 3.6.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/badce355-e6ce-4dd4-8d9b-c87a7b9db12f/

Credits

Revanth Hari Narayana Matte WPScan