CVE-2026-16954: AI Engine < 3.6.4 - Editor+ Sensitive Information Disclosure of API Key and Bearer Tokens
The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admin page's inline script data, allowing users with the Editor role to read the site's stored third-party API key and authentication tokens in cleartext, despite those secrets being restricted to administrators everywhere else.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress AI Engine pluginto a version that resolves this vulnerability.Fixed in 3.6.4 - Operational
After upgrading, rotate the exposed third-party API key and authentication tokens because they may have been disclosed to users with the Editor role in cleartext.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16954?
The severity of CVE-2026-16954 is rated at 51, indicating a moderate risk.
How do I fix CVE-2026-16954?
To fix CVE-2026-16954, update the AI Engine plugin to version 3.6.4 or later.
Who is affected by CVE-2026-16954?
Users with the Editor role in WordPress sites using AI Engine versions before 3.6.4 are affected by CVE-2026-16954.
What kind of information is disclosed in CVE-2026-16954?
CVE-2026-16954 allows disclosure of sensitive information such as API keys and authentication tokens in cleartext.
What is the impact of CVE-2026-16954 on WordPress sites?
The impact of CVE-2026-16954 includes potential unauthorized access to third-party services due to exposed secret configuration values.