CVE

CVE-2026-16954 — AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.6.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-16954 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.6.4 Exposure of Sensitive Information to an Unauthorized Actor Unknown < 3.6.4 3.6.4 2026-08-06

CVE-2026-16954

A vulnerability exists in AI Engine WordPress plugin versions prior to 3.6.4, where sensitive configuration settings are not properly obscured when displayed on an administrative page's inline JavaScript code, enabling users with Editor privileges to access the site's third-party API credentials and authentication details in plain text format. This exposure occurs despite these secrets being restricted to administrator-level access elsewhere within the platform.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.