CVE · High

CVE-2026-27407 — AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.5.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-27407 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.5.0 Incorrect Privilege Assignment High 7.2 < 3.5.0 3.5.0 2026-05-28

CVE-2026-27407

The AI Engine plugin for WordPress suffers from a privilege escalation flaw affecting all versions prior to 3.4.10, allowing users with elevated permissions to gain unauthorized control over the site's functionality. This vulnerability can be exploited by authenticated attackers holding editor or higher-level access.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.