SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-12510

MEDIUM · CVSS 5.9 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The AI Engine WordPress plugin prior to version 3.5.5 is vulnerable due to inadequate verification of user ownership for chatbot conversations, allowing subscribers to access and potentially hijack private conversations of other users. This could lead to unauthorized disclosure of sensitive information and compromise user privacy. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-12510
Severity
MEDIUM
CVSS
5.9
EPSS
0.14%
WordPress

Original NVD Description

The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, allowing users with subscriber-level access to read other users' private conversations and take over their conversation records when the discussions feature is enabled.