CVE · High

CVE-2026-15988 — AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.6.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15988 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.6.6 Cross-Site Request Forgery (CSRF) High 8.8 < 3.6.6 3.6.6 2026-07-31

CVE-2026-15988

The AI Engine – The Chatbot plugin for WordPress contains a security flaw in versions up to 3.6.5 that allows malicious individuals to exploit a vulnerability through manipulated links. This is caused by inadequate verification of authentication tokens when accessing certain functions, specifically reauth_for_authorize. As a result, an attacker can create new administrator accounts with their own chosen credentials without needing prior access or authorization.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.