Description
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via the 'mediaId' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to access and retrieve the transcribed contents of private audio attachments belonging to other users, including Administrators, via a supplied attachment ID. This vulnerability requires the Public API module to be enabled in the plugin settings; when disabled, the REST route is absent and the endpoint returns HTTP 404.
Published: 2026-09-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Insecure Direct Object Reference allowing retrieval of private audio attachment contents
Action: Apply patch
AI Analysis

Impact

The AI Engine WordPress plugin or higher privileges to request the transcription of any audio attachment by supplying its media ID. Because the plugin performs no ownership check on the mediaId parameter, an attacker can read the contents of other users’ private audio files. This is a data disclosure vulnerability that can compromise confidentiality of user data.

Affected Systems

All versions, AI Framework & MCP for WordPress plugin up to and including 3.7.7 are affected. The vulnerability is triggered when the Public API module is enabled; versions with the module disabled do not expose the vulnerable REST endpoint.

Risk and Exploitability

The CVSS score of 6.5 reflects a moderate severity data‑disclosure risk. The EPSS score indicates an extremely low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need authenticated access with subscriber or higher privileges and an active Public API module to exploit the error in ownership validation via the mediaId query parameter.

Generated by OpenCVE AI on September 17, 2026 at 18:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade AI Engine to the latest version that includes the mediaId ownership validation patch
  • If unable to upgrade immediately, disable the Public API module in the plugin settings to remove the insecure REST route
  • Configure WordPress or the plugin to restrict REST API access for the transcription endpoint to Administrator role only, or block the endpoint via server configuration for non‑admin users

Generated by OpenCVE AI on September 17, 2026 at 18:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via the 'mediaId' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to access and retrieve the transcribed contents of private audio attachments belonging to other users, including Administrators, via a supplied attachment ID. This vulnerability requires the Public API module to be enabled in the plugin settings; when disabled, the REST route is absent and the endpoint returns HTTP 404.
Title AI Engine <= 3.7.7 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Attachment Disclosure via 'mediaId' Parameter
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-15T13:53:51.020Z

Reserved: 2026-09-10T23:37:42.478Z

Link: CVE-2026-89141

cve-icon Vulnrichment

Updated: 2026-09-15T13:25:17.631Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T07:16:31.460

Modified: 2026-09-15T14:37:14.523

Link: CVE-2026-89141

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key