CVE-2026-16955
Received Received - Intake

File Read and Exfiltration in AI Engine WordPress Plugin

Vulnerability report for CVE-2026-16955, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-08

Last updated on: 2026-08-08

Assigner: WPScan

Description

The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature to be enabled; otherwise the same issue is reachable by an administrator, which on multisite allows a non-super subsite administrator to read the network-shared configuration and its secrets.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-08
Last Modified
2026-08-08
Generated
2026-08-08
AI Q&A
2026-08-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ai_engine ai_engine to 3.6.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The AI Engine WordPress plugin before version 3.6.6 has a vulnerability where it does not properly validate file paths before reading them. This allows users with subscriber-level access to read arbitrary files from the server and send them to an external service. The issue requires a non-default public API feature to be enabled for subscriber access; otherwise, administrators can exploit it. On multisite installations, non-super administrators can read network-shared configurations and secrets.

Detection Guidance

Check if the AI Engine WordPress plugin is installed and verify its version. If it is below 3.6.6, the system is vulnerable. Use commands like 'wp plugin list' in WordPress or inspect the plugin directory for version details.

Impact Analysis

This vulnerability can allow unauthorized users to read sensitive files on your server, including configuration files, secrets, or other confidential data. Attackers could exfiltrate this data off-host, leading to potential data breaches, loss of sensitive information, or further compromise of your system.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, or other regulations by exposing personal or sensitive data. Unauthorized access to such data may result in legal penalties, reputational damage, and loss of trust from users or clients.

Mitigation Strategies

Update the AI Engine plugin to version 3.6.6 or later immediately. If updating is not possible, disable the plugin or restrict access to the public API feature if it is enabled.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16955. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart