CVE-2026-75798: Unknown Ai Engine

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only features, relying instead on a token it hands out to anonymous visitors, allowing unauthenticated attackers to run AI queries of their own choosing against the site owner's configured provider account.

Affected products

  • Unknown Ai Engine: from 3.4.0, before 3.7.2 (fixed in 3.7.2)

Published 2026-08-26. Last modified 2026-08-26.