CVE-2026-93623: WordPress AI Engine plugin <= 3.7.8 - Insecure Direct Object References (IDOR) vulnerability
Published Sep 23, 2026
·Updated
Unauthenticated Insecure Direct Object References (IDOR) in AI Engine <= 3.7.8 versions.
Affected Software
1 affected component
Meow Apps AI Engine<=3.7.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress AI Engine Pluginto a version that resolves this vulnerability.Fixed in 3.7.9
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior privileges to attempt exploitation.
2
Which versions are affected?
AI Engine versions 3.7.8 and earlier are identified as affected.
3
What is the potential impact?
The supplied severity vector indicates low confidentiality impact, with no integrity or availability impact specified.