CVE Database /
CVE-2026-16954
CVE
CVE-2026-16954 — AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.6.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-16954
|
AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.6.4 |
Exposure of Sensitive Information to an Unauthorized Actor |
Unknown
|
< 3.6.4
|
3.6.4 |
2026-08-06 |
—
|
CVE-2026-16954
A vulnerability exists in AI Engine WordPress plugin versions prior to 3.6.4, where sensitive configuration settings are not properly obscured when displayed on an administrative page's inline JavaScript code, enabling users with Editor privileges to access the site's third-party API credentials and authentication details in plain text format. This exposure occurs despite these secrets being restricted to administrator-level access elsewhere within the platform.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings