CVE-2026-12510: Unknown Ai Engine

Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.

The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, allowing users with subscriber-level access to read other users' private conversations and take over their conversation records when the discussions feature is enabled.

Affected products

  • Unknown Ai Engine: before 3.5.5 (fixed in 3.5.5)

Published 2026-07-16. Last modified 2026-07-16.