CyberRota Analysis
AI-GeneratedThe AI Engine WordPress plugin prior to version 3.6.1 has a vulnerability that allows unauthorized users with Administrator privileges on a Multisite sub-site to perform user management operations, potentially taking over any account within the network, including that of the Network Administrator. This poses a significant security risk, as it can lead to unauthorized access and control over the entire WordPress network. WordPress administrators, particularly those managing Multisite environments, should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing privileged user management operations, allowing users with the Administrator role on a Multisite sub-site to take over any account on the network, including the Network Administrator's.