CVE

CVE-2026-16955 — AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.6.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-16955 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.6.6 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Unknown < 3.6.6 3.6.6 2026-08-08

CVE-2026-16955

The AI Engine WordPress plugin contains a vulnerability in versions prior to 3.6.6, where it fails to properly validate file paths before processing them. This oversight enables attackers with subscriber-level access to access and extract arbitrary server files, provided that a specific public API feature is enabled or an administrator account exists on the network.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.