Impact
The AI Engine WordPress plugin fails to verify that the user executing privileged user‑management operations has appropriate authorization. This omission lets anyone with the Administrator role on a multisite sub‑site perform account takeover on the entire network, including the Network Administrator account. The resulting unauthorized access grants full control over the WordPress installation, exposing site content, configuration, and all other users’ data and allowing any additional malicious activity once the attacker controls the Network Administrator. By bypassing access controls on user‑management actions, the vulnerability qualifies as a classic authorization bypass. An attacker could leverage the Mcp User Tools interface, which is accessible to sub‑site administrators, to alter ownership or credentials of any account across the network. Because the flaw exists in several major plugin releases, the potential impact covers all WordPress multisite sites running a vulnerable version of AI Engine. The gain is complete administrative control over the multisite network, representing the highest risk on the integrity, confidentiality, and availability dimensions. Any attacker who can reach a sub‑site’s Admin console thereby eliminates the need for further attacks, making this an especially powerful vector for exploitation.
Affected Systems
AI Engine WordPress plugin, versions preceding 3.6.1. The vulnerability applies to any multisite environment where the plugin is installed and a sub‑site administrator has the Administrator capability. The affected vendor is the unknown company behind AI Engine.
Risk and Exploitability
Because the flaw is an authorization bypass, exploitation requires that an attacker first obtain or assume Administrator access on at least one sub‑site. Once that condition is met, the attacker can traverse the network by using the user‑management tools to take over any account, including the Network Administrator. No public exploits are known at this time, and the EPSS score is unavailable; however, the absence of a defensive check coupled with the high‑value target (the Network Administrator) renders the vulnerability a high‑risk concern. The vulnerability is not listed in CISA’s KEV catalog, but the lack of official remedy in the brief suggests an urgent need for patching or remediation. Overall, the situation is one where a patch or fix should be applied immediately, as an attacker who can reach a sub‑site Admin account can effectively seize full control of the entire WordPress network.
OpenCVE Enrichment