Impact
The AI Engine WordPress plugin or higher privileges to request the transcription of any audio attachment by supplying its media ID. Because the plugin performs no ownership check on the mediaId parameter, an attacker can read the contents of other users’ private audio files. This is a data disclosure vulnerability that can compromise confidentiality of user data.
Affected Systems
All versions, AI Framework & MCP for WordPress plugin up to and including 3.7.7 are affected. The vulnerability is triggered when the Public API module is enabled; versions with the module disabled do not expose the vulnerable REST endpoint.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity data‑disclosure risk. The EPSS score indicates an extremely low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need authenticated access with subscriber or higher privileges and an active Public API module to exploit the error in ownership validation via the mediaId query parameter.
OpenCVE Enrichment