CVE-2026-39506: WordPress AI Engine (Pro) plugin < 3.4.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in Jordy Meow AI Engine (Pro) ai-engine-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Engine (Pro): from n/a through < 3.4.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Jordy Meow AI Engine (Pro) / WordPress AI Engine (Pro) pluginto a version that resolves this vulnerability.Fixed in 3.4.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39506?
The severity of CVE-2026-39506 is medium, with a score of 4.3.
How do I fix CVE-2026-39506?
To fix CVE-2026-39506, update the Jordy Meow AI Engine (Pro) plugin to version 3.4.2 or later.
What type of vulnerability is CVE-2026-39506?
CVE-2026-39506 is a Broken Access Control vulnerability.
Which versions of AI Engine (Pro) are affected by CVE-2026-39506?
CVE-2026-39506 affects versions of AI Engine (Pro) from n/a through version 3.4.1.
What can be exploited in CVE-2026-39506?
CVE-2026-39506 can be exploited due to incorrectly configured access control security levels.