CVE

CVE-2026-16953 — AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.6.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-16953 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.6.4 Authorization Bypass Through User-Controlled Key Unknown < 3.6.4 3.6.4 2026-08-08

CVE-2026-16953

The AI Engine WordPress plugin prior to version 3.6.4 contains a security flaw that allows unauthorized deletion of user-uploaded chatbot files. This vulnerability arises from the plugin's failure to properly authenticate the owner of these files before allowing their removal, instead relying on a session cookie value provided by the client. As a result, an attacker can exploit this weakness by obtaining a victim's session ID and file reference, then deleting the associated uploaded files without needing authentication.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.