CVE-2026-75798 PUBLISHED

AI Engine 3.4.0 - 3.7.1 - Unauthenticated Arbitrary AI Query Execution via Editor Assistant

Assigner: WPScan
Reserved: 18.08.2026 Published: 26.08.2026 Updated: 26.08.2026

The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only features, relying instead on a token it hands out to anonymous visitors, allowing unauthenticated attackers to run AI queries of their own choosing against the site owner's configured provider account.

Product Status

Vendor Unknown
Product AI Engine
Versions Default: unaffected
  • affected from 3.4.0 to 3.7.2 (excl.)

Credits

  • Abdullah Kareem finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE