PT-2026-41513 · WordPress · Ai Engine
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The AI Engine – The Chatbot, AI Framework & MCP for WordPress version 3.4.9
Description
Missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path allows authenticated users with Subscriber privileges or higher to gain unauthorized access. Because the system grants MCP access to any valid OAuth token without verifying administrator privileges, attackers can invoke admin-level MCP tools to escalate their privileges to Administrator.
Recommendations
Update The AI Engine – The Chatbot, AI Framework & MCP for WordPress to a version later than 3.4.9.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ai Engine