Impact
The AI Engine WordPress plugin prior to version 3.6.6 fails to validate caller‑supplied file paths when processing requests sent to an external transcription service. A subscriber‑level user who enables the non‑default public API feature can supply any file path on the host, causing the plugin to read that file and forward its contents to a third‑party endpoint, thereby exfiltrating data off‑host. The flaw is a pure confidentiality breach: it does not crash the server or affect availability, but grants attackers read access to arbitrary files on the WordPress installation, including sensitive configuration data.
Affected Systems
The vulnerability affects the AI Engine plugin for WordPress as distributed by the vendor "Unknown:AI Engine". All installations of the plugin earlier than 3.6.6 are potentially impacted. Sites that have enabled the non‑default public API feature expose any subscriber account to the read capability, while an administrator or a non‑super subsite administrator in a multisite environment can also exploit the flaw to read shared configuration secrets.
Risk and Exploitability
The exploit requires either subscriber‑level access with the public API feature turned on or higher (administrator) privileges. On multisite networks, a non‑super subsite administrator can abuse the defect to read network‑shared files. Because no EPSS data is published and the issue is not listed in the CISA KEV catalog, the public exploitation likelihood is currently unknown, but the high confidentiality impact suggests that credentialed attackers could leverage the flaw for real‑world data theft. The CVSS score is not provided, yet the nature of the flaw points to a severe rating in most vulnerability scoring guidelines.
OpenCVE Enrichment