CVE

CVE-2026-12510 — AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.5.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12510 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.5.5 Authorization Bypass Through User-Controlled Key Unknown < 3.5.5 3.5.5 2026-06-25

CVE-2026-12510

The WordPress plugin "AI Engine – The Chatbot" has a security flaw in versions up to 3.5.4 that allows unauthorized access to private chat data. A specific key is not properly checked for authenticity, enabling attackers with sufficient privileges to view conversations they shouldn't be able to see. This vulnerability affects all users with Custom-level access or higher.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.