CVE-2026-75796: AI Engine 2.8.0 - 3.6.0 - Admin+ Multisite Network Administrator Account Takeover via MCP User Tools
The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing privileged user management operations, allowing users with the Administrator role on a Multisite sub-site to take over any account on the network, including the Network Administrator's.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
The issue affects WordPress Multisite installations using AI Engine versions before 3.6.1. A user must hold the Administrator role on a Multisite sub-site to exploit it.
What level of access does an attacker need, and what could they gain?
An attacker needs an existing Administrator account on any sub-site in the network. They can perform privileged user-management actions against accounts elsewhere on the network, including taking over the Network Administrator account.
What should be prioritized for remediation?
Update AI Engine to version 3.6.1 or later. Until updating is possible, restrict and review Administrator access on Multisite sub-sites because those accounts provide the prerequisite access for exploitation.