CVE-2026-12510
Deferred Deferred - Pending Action

WordPress AI Engine Plugin Unauthorized Chatbot Access

Vulnerability report for CVE-2026-12510, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-16

Last updated on: 2026-07-16

Assigner: WPScan

Description

The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, allowing users with subscriber-level access to read other users' private conversations and take over their conversation records when the discussions feature is enabled.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-16
Last Modified
2026-07-16
Generated
2026-08-05
AI Q&A
2026-07-16
EPSS Evaluated
2026-08-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ai_engine plugin to 3.5.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-12510 is an Insecure Direct Object Reference (IDOR) vulnerability in the AI Engine WordPress plugin before version 3.5.5. It allows users with subscriber-level access to read private chatbot conversations of other users and take over those conversations by reassigning ownership. The issue occurs because the plugin does not verify if a user owns the chatbot conversation referenced by a client-supplied identifier.

Detection Guidance

Check if the AI Engine WordPress plugin version is below 3.5.5. Inspect chatbot discussions for unauthorized access or ownership changes. Look for subscriber accounts accessing conversations not belonging to them.

Impact Analysis

If you use the AI Engine plugin with the discussions feature enabled and have subscriber-level access, an attacker could exploit this vulnerability to read your private conversations and take over your chatbot discussions. This requires the attacker to know your chat ID, which might be exposed through default settings or browser history.

Compliance Impact

This vulnerability could lead to unauthorized access to private chatbot conversations, potentially exposing sensitive personal data. For GDPR, this may violate principles of data minimization and security, risking fines for inadequate protection of personal data. Under HIPAA, if the conversations involve protected health information, the breach could result in compliance violations and penalties for failing to secure patient data.

Mitigation Strategies

Update the AI Engine plugin to version 3.5.5 or later immediately. Review and remove any unauthorized access to chatbot discussions. Disable the discussions feature if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12510. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart