Description
The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing privileged user management operations, allowing users with the Administrator role on a Multisite sub-site to take over any account on the network, including the Network Administrator's.
Published: 2026-08-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized privilege escalation allowing network administrator takeover on multisite installations
Action: Update plugin
AI Analysis

Impact

The AI Engine WordPress plugin versions prior to 3.6.1 fails to verify that the requesting user has authorization to act on the targeted account before executing privileged user‑management operations. This lapse in authorization checks allows a user with Administrator privileges on a multisite sub‑site to take over any account on the entire network, including the Network Administrator. As a result, an attacker gains full control over the multisite WordPress installation, able to manipulate content, configuration, and all user data, and to conduct further malicious activity. The weakness is an improper privilege management flaw identified by CWE‑269.

Affected Systems

Affected systems are sites using the AI Engine WordPress plugin with a version earlier than 3.6.1 running in a multisite configuration. The vulnerability applies to any network where a sub‑site Administrator role exists and has access to the MCP User Tools. The vendor is an unknown entity behind AI Engine, so users must check for updates from the plugin repository or the developer.

Risk and Exploitability

Based on the description, it is inferred that the attack vector involves the MCP User Tools interface, which is accessible to sub‑site administrators. An attacker must first obtain or assume Administrator access on at least one sub‑site; once that condition is satisfied, the privilege‑bypass allows traversal of the network to take over any account, including the Network Administrator. The CVSS score of 7.2 indicates high severity, while the EPSS score of < 1% suggests a very low but non‑zero likelihood of public exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the flaw permits complete administrative control over the network, it represents a significant risk to confidentiality, integrity, and availability.

Generated by OpenCVE AI on August 21, 2026 at 17:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the AI Engine plugin to version 3.6.1 or later, where the privilege‑checks for user‑management operations have been added.
  • If an upgrade cannot be performed promptly, restrict sub‑site Administrator roles from accessing the MCP User Tools, or otherwise revoke their ability to edit or change user accounts beyond their own site.
  • Enable auditing of user‑management changes and review the list of users for any unexpected ownership changes, enforcing least‑privilege so that only the Network Administrator manages users across the entire multisite network.

Generated by OpenCVE AI on August 21, 2026 at 17:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Ai Engine Project
Ai Engine Project ai Engine
Wordpress
Wordpress wordpress
Vendors & Products Ai Engine Project
Ai Engine Project ai Engine
Wordpress
Wordpress wordpress

Fri, 21 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 21 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing privileged user management operations, allowing users with the Administrator role on a Multisite sub-site to take over any account on the network, including the Network Administrator's.
Title AI Engine 2.8.0 - 3.6.0 - Admin+ Multisite Network Administrator Account Takeover via MCP User Tools
References

Subscriptions

Ai Engine Project Ai Engine
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-21T12:52:37.603Z

Reserved: 2026-08-18T09:03:55.399Z

Link: CVE-2026-75796

cve-icon Vulnrichment

Updated: 2026-08-21T12:52:18.278Z

cve-icon NVD

Status : Deferred

Published: 2026-08-21T07:16:25.453

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-75796

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T18:00:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management