Skip to content
HighVulnerabilityLLM-specific

CVE-2026-96561: AI Engine WordPress plugin stored cross-site scripting via chat REST endpoint

Identifier
CVE-2026-96561
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.3%

Summary

The AI Engine plugin for WordPress, up to and including 3.8.0, contains a stored cross-site scripting flaw. An unauthenticated attacker can send crafted input to the /mwai-ui/v1/chats/submit REST endpoint, which writes an attacker-controlled string into the PHP error log as a forged line. The plugin's Advisor feature then passes that content into an AI prompt and stores the result unescaped, so the injected script runs when an administrator opens the WordPress dashboard.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.