The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path, where any valid OAuth token causes MCP access to be granted without verifying administrator privileges. This makes it possible for authenticated (Subscriber+) attackers to invoke admin-level MCP tools and escalate privileges to Administrator.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 17 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tigroumeow
Tigroumeow ai Engine – The Chatbot And Ai Framework For Wordpress Wordpress Wordpress wordpress |
|
| Vendors & Products |
Tigroumeow
Tigroumeow ai Engine – The Chatbot And Ai Framework For Wordpress Wordpress Wordpress wordpress |
Sun, 17 May 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path, where any valid OAuth token causes MCP access to be granted without verifying administrator privileges. This makes it possible for authenticated (Subscriber+) attackers to invoke admin-level MCP tools and escalate privileges to Administrator. | |
| Title | AI Engine 3.4.9 - Authenticated (Subscriber+) Privilege Escalation via Missing Authorization in MCP OAuth Bearer Token | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-17T02:27:02.277Z
Reserved: 2026-05-15T21:30:51.096Z
Link: CVE-2026-8719
No data.
Status : Received
Published: 2026-05-17T04:16:42.580
Modified: 2026-05-17T04:16:42.580
Link: CVE-2026-8719
No data.
OpenCVE Enrichment
Updated: 2026-05-17T17:00:26Z
Weaknesses