Impact
The AI Engine WordPress plugin versions prior to 3.6.1 fails to verify that the requesting user has authorization to act on the targeted account before executing privileged user‑management operations. This lapse in authorization checks allows a user with Administrator privileges on a multisite sub‑site to take over any account on the entire network, including the Network Administrator. As a result, an attacker gains full control over the multisite WordPress installation, able to manipulate content, configuration, and all user data, and to conduct further malicious activity. The weakness is an improper privilege management flaw identified by CWE‑269.
Affected Systems
Affected systems are sites using the AI Engine WordPress plugin with a version earlier than 3.6.1 running in a multisite configuration. The vulnerability applies to any network where a sub‑site Administrator role exists and has access to the MCP User Tools. The vendor is an unknown entity behind AI Engine, so users must check for updates from the plugin repository or the developer.
Risk and Exploitability
Based on the description, it is inferred that the attack vector involves the MCP User Tools interface, which is accessible to sub‑site administrators. An attacker must first obtain or assume Administrator access on at least one sub‑site; once that condition is satisfied, the privilege‑bypass allows traversal of the network to take over any account, including the Network Administrator. The CVSS score of 7.2 indicates high severity, while the EPSS score of < 1% suggests a very low but non‑zero likelihood of public exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the flaw permits complete administrative control over the network, it represents a significant risk to confidentiality, integrity, and availability.
OpenCVE Enrichment