CVE-2026-75797
Received Received - Intake

Path Traversal in AI Engine WordPress Plugin

Vulnerability report for CVE-2026-75797, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: WPScan

Description

The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local filesystem path before reading the file and forwarding its contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature to be enabled; otherwise the same issue is reachable by an administrator, which on multisite allows a non-super subsite administrator to read the network-shared configuration and its secrets.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-26
AI Q&A
2026-08-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ai_engine wordpress_plugin to 3.7.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The AI Engine WordPress plugin before version 3.7.2 has a vulnerability where it does not properly validate a user-supplied URL before using it to access local files. This allows attackers with subscriber-level access to read arbitrary files from the server and send them to external services. If a specific public API feature is disabled, administrators can exploit this issue. On multisite setups, non-super subsite administrators can access shared network configurations and secrets.

Detection Guidance

Check if the AI Engine WordPress plugin version is between 3.3.3 and 3.7.1. Look for unusual file access patterns or requests to the vulnerable 'url' parameter in server logs.

Impact Analysis

This vulnerability can allow unauthorized users to read sensitive files on your server, including configuration files, secrets, or other confidential data. Attackers could exfiltrate this data to external servers, leading to potential data breaches, loss of sensitive information, or further compromise of your system.

Compliance Impact

This vulnerability could lead to non-compliance with regulations like GDPR or HIPAA by exposing sensitive personal or health data. Unauthorized access to such data may result in legal penalties, reputational damage, and loss of trust from users or clients.

Mitigation Strategies

Update the AI Engine plugin to version 3.7.2 or later immediately. If updating is not possible, disable the plugin or restrict access to the vulnerable functionality.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75797. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart