CVE-2026-16955: AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio Transcription
The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature to be enabled; otherwise the same issue is reachable by an administrator, which on multisite allows a non-super subsite administrator to read the network-shared configuration and its secrets.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AI Engine WordPress pluginto a version that resolves this vulnerability.Fixed in 3.6.6 - Configuration
Disable the non-default public API feature that is required to reach the issue at subscriber level; otherwise the issue is reachable by an administrator (multisite) who could allow a non-super subsite administrator to access network-shared configuration and secrets.
AI Engine WordPress plugin non-default public API feature (subscriber+ reachability) = disable
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16955?
CVE-2026-16955 has a risk rating of 55, indicating a moderate severity level.
How do I fix CVE-2026-16955?
To fix CVE-2026-16955, update the AI Engine WordPress plugin to version 3.6.6 or later.
Who is affected by CVE-2026-16955?
Users with a subscriber-level account on WordPress sites using the AI Engine plugin before version 3.6.6 are affected by CVE-2026-16955.
What type of vulnerability is CVE-2026-16955?
CVE-2026-16955 is classified as a Path Traversal vulnerability.
What can attackers do with CVE-2026-16955?
Attackers can leverage CVE-2026-16955 to read arbitrary files from the server and exfiltrate the information to external services.