SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-75796

HIGH · CVSS 7.2 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The AI Engine WordPress plugin prior to version 3.6.1 has a vulnerability that allows unauthorized users with Administrator privileges on a Multisite sub-site to perform user management operations, potentially taking over any account within the network, including that of the Network Administrator. This poses a significant security risk, as it can lead to unauthorized access and control over the entire WordPress network. WordPress administrators, particularly those managing Multisite environments, should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-75796
Severity
HIGH
CVSS
7.2
EPSS
0.26%
WordPress

Original NVD Description

The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing privileged user management operations, allowing users with the Administrator role on a Multisite sub-site to take over any account on the network, including the Network Administrator's.