Description
The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature to be enabled; otherwise the same issue is reachable by an administrator, which on multisite allows a non-super subsite administrator to read the network-shared configuration and its secrets.
Published: 2026-08-08
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The AI Engine WordPress plugin prior to version 3.6.6 fails to validate caller‑supplied file paths when processing requests sent to an external transcription service. A subscriber‑level user who enables the non‑default public API feature can supply any file path on the host, causing the plugin to read that file and forward its contents to a third‑party endpoint, thereby exfiltrating data off‑host. The flaw is a pure confidentiality breach: it does not crash the server or affect availability, but grants attackers read access to arbitrary files on the WordPress installation, including sensitive configuration data.

Affected Systems

The vulnerability affects the AI Engine plugin for WordPress as distributed by the vendor "Unknown:AI Engine". All installations of the plugin earlier than 3.6.6 are potentially impacted. Sites that have enabled the non‑default public API feature expose any subscriber account to the read capability, while an administrator or a non‑super subsite administrator in a multisite environment can also exploit the flaw to read shared configuration secrets.

Risk and Exploitability

The exploit requires either subscriber‑level access with the public API feature turned on or higher (administrator) privileges. On multisite networks, a non‑super subsite administrator can abuse the defect to read network‑shared files. Because no EPSS data is published and the issue is not listed in the CISA KEV catalog, the public exploitation likelihood is currently unknown, but the high confidentiality impact suggests that credentialed attackers could leverage the flaw for real‑world data theft. The CVSS score is not provided, yet the nature of the flaw points to a severe rating in most vulnerability scoring guidelines.

Generated by OpenCVE AI on August 8, 2026 at 07:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the AI Engine plugin to version 3.6.6 or later.
  • If an upgrade is not immediately feasible, disable the public API feature that accepts arbitrary file paths or remove the plugin entirely from the site.
  • For multisite installations, verify that only super‑site administrators can use the API or explicitly deny read access to configuration files for non‑super subsite administrators.

Generated by OpenCVE AI on August 8, 2026 at 07:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22

Sat, 08 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature to be enabled; otherwise the same issue is reachable by an administrator, which on multisite allows a non-super subsite administrator to read the network-shared configuration and its secrets.
Title AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio Transcription
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-08T06:00:13.729Z

Reserved: 2026-07-24T08:07:58.902Z

Link: CVE-2026-16955

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T07:30:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')