CVE Database /
CVE-2026-12510
CVE
CVE-2026-12510 — AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.5.5
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-12510
|
AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.5.5 |
Authorization Bypass Through User-Controlled Key |
Unknown
|
< 3.5.5
|
3.5.5 |
2026-06-25 |
—
|
CVE-2026-12510
The WordPress plugin "AI Engine – The Chatbot" has a security flaw in versions up to 3.5.4 that allows unauthorized access to private chat data. A specific key is not properly checked for authenticity, enabling attackers with sufficient privileges to view conversations they shouldn't be able to see. This vulnerability affects all users with Custom-level access or higher.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings