CVE-2026-16954 PUBLISHED

AI Engine < 3.6.4 - Editor+ Sensitive Information Disclosure of API Key and Bearer Tokens

Assigner: WPScan
Reserved: 24.07.2026 Published: 06.08.2026 Updated: 06.08.2026

The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admin page's inline script data, allowing users with the Editor role to read the site's stored third-party API key and authentication tokens in cleartext, despite those secrets being restricted to administrators everywhere else.

Product Status

Vendor Unknown
Product AI Engine
Versions Default: unaffected
  • affected from 0 to 3.6.4 (excl.)

Credits

  • Revanth Hari Narayana Matte finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE