CVE-2026-16953
Received Received - Intake

Unauthenticated File Deletion in AI Engine WordPress Plugin

Vulnerability report for CVE-2026-16953, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-08

Last updated on: 2026-08-08

Assigner: WPScan

Description

The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deletion, authorising the action solely by a client-supplied session cookie value, so an unauthenticated attacker who obtains a victim's session identifier and file reference can delete that victim's uploaded files.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-08
Last Modified
2026-08-08
Generated
2026-08-08
AI Q&A
2026-08-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ai_engine plugin to 3.6.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The AI Engine WordPress plugin before version 3.6.4 has a flaw where it deletes guest-uploaded chatbot files without verifying ownership. It relies only on a session cookie provided by the client, allowing an attacker who steals a victim's session ID and knows the file reference to delete those files without authentication.

Detection Guidance

This vulnerability can be detected by checking the version of the AI Engine WordPress plugin. If the version is below 3.6.4, the system is vulnerable. Inspect the plugin files for improper session cookie validation in file deletion operations.

Impact Analysis

If you use the AI Engine plugin before version 3.6.4, an attacker could delete your uploaded chatbot files by obtaining your session cookie. This could disrupt your website's functionality or cause data loss if those files are important.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized deletion of user-uploaded files. Under GDPR, unauthorized deletion may constitute a violation of data integrity and access controls. HIPAA requires strict access controls to protect sensitive health data, which could be compromised if files are deleted without proper authorization.

Mitigation Strategies

Immediately update the AI Engine plugin to version 3.6.4 or later. Review and restrict file deletion permissions to authenticated users with verified ownership. Monitor for unauthorized file deletions or suspicious session activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16953. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart