SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-12511

HIGH · CVSS 8.1 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

The AI Engine WordPress plugin prior to version 3.5.5 is vulnerable to a path traversal attack, allowing authenticated users with editor-level access to write arbitrary files to the server by exploiting unsanitized user-supplied filenames. This could lead to unauthorized file manipulation or server compromise. WordPress site administrators and security teams should prioritize this vulnerability to mitigate potential exploitation risks.

CVE
CVE-2026-12511
Severity
HIGH
CVSS
8.1
EPSS
0.29%
WordPress

Original NVD Description

The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authenticated users with editor-level access to write attacker-controlled bytes to an arbitrary location on the server via path traversal.