CVE · High

CVE-2026-65545 — AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.6.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-65545 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.6.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.6.9 3.6.9 2026-07-28

CVE-2026-65545

The AI Engine plugin for WordPress contains a security flaw in versions up to 3.6.8, allowing malicious code injection through insufficient validation of user input. As a result, unverified visitors can embed executable scripts on websites that will run when users access the compromised pages. This vulnerability enables attackers to execute arbitrary web content without requiring authentication.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.