CVE-2026-12510: AI Engine < 3.5.5 - Subscriber+Chatbot Discussion Disclosure and Takeover via IDOR
The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, allowing users with subscriber-level access to read other users' private conversations and take over their conversation records when the discussions feature is enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress AI Engine pluginto a version that resolves this vulnerability.Fixed in 3.5.5 - Compensating control
Ensure the Discussions feature is disabled in the AI Engine WordPress plugin until the plugin is updated, to reduce risk of IDOR-based disclosure/takeover.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12510?
CVE-2026-12510 has a risk score of 57, indicating a moderate level of severity.
How do I fix CVE-2026-12510?
To fix CVE-2026-12510, update the AI Engine WordPress plugin to version 3.5.5 or later.
What does CVE-2026-12510 affect?
CVE-2026-12510 affects the AI Engine WordPress plugin prior to version 3.5.5.
What type of vulnerability is CVE-2026-12510?
CVE-2026-12510 is an Insecure Direct Object Reference (IDOR) vulnerability.
Who is impacted by CVE-2026-12510?
CVE-2026-12510 can impact users with subscriber-level access, allowing them to view and take over private chatbot conversations.