CVE Database /
CVE-2026-27407
CVE · High
CVE-2026-27407 — AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.5.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-27407
|
AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.5.0 |
Incorrect Privilege Assignment |
High
7.2
|
< 3.5.0
|
3.5.0 |
2026-05-28 |
—
|
CVE-2026-27407
The AI Engine plugin for WordPress suffers from a privilege escalation flaw affecting all versions prior to 3.4.10, allowing users with elevated permissions to gain unauthorized control over the site's functionality. This vulnerability can be exploited by authenticated attackers holding editor or higher-level access.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings