CVE-2026-75798: AI Engine 3.4.0 - 3.7.1 - Unauthenticated Arbitrary AI Query Execution via Editor Assistant
The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only features, relying instead on a token it hands out to anonymous visitors, allowing unauthenticated attackers to run AI queries of their own choosing against the site owner's configured provider account.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress AI Engine pluginto a version that resolves this vulnerability.Fixed in 3.7.2
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated visitor who can obtain the token issued by the affected site can submit AI queries. The issue does not require a logged-in WordPress account because the affected feature lacks an authorization check.
What is the practical impact for the site owner?
An attacker can run AI queries of their choosing through the site owner's configured AI provider account. This can result in unauthorized use of that provider account.
Which versions are affected?
AI Engine versions 3.4.0 through 3.7.1 are affected. Versions before 3.7.2 are described as lacking the required authorization check.