๐Ÿ” CVE Alert

CVE-2026-75798

MEDIUM 5.3

AI Engine 3.4.0 - 3.7.1 - Unauthenticated Arbitrary AI Query Execution via Editor Assistant

CVSS Score
5.3
EPSS Score
0.2%
EPSS Percentile
6th

The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only features, relying instead on a token it hands out to anonymous visitors, allowing unauthenticated attackers to run AI queries of their own choosing against the site owner's configured provider account.

Vendor unknown
Product ai engine
Published Aug 26, 2026
Last Updated Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for unknown ai engine

Be the first to know when new medium vulnerabilities affecting unknown ai engine are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / AI Engine
3.4.0 < 3.7.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/a77168df-61b8-40df-95f5-e19cf6540ce5/

Credits

Abdullah Kareem WPScan