8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path, where any valid OAuth token causes MCP access to be granted without verifying administrator privileges. This makes it possible for authenticated (Subscriber+) attackers to invoke admin-level MCP tools and escalate privileges to Administrator.
AI Analysis
Privilege Escalation vulnerability due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path
Basic Information
ID
CVE-2026-8719
Source
Wordfence
Published
May 17, 2026 at 02:27
Affected Product
Vendor
tigroumeow
Product
AI Engine – The Chatbot, AI Framework & MCP for WordPress
Version
3.4.9
Affected Versions
tigroumeow AI Engine – The Chatbot, AI Framework & MCP for WordPress 3.4.9
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
tigroumeow
Product
AI Engine – The Chatbot, AI Framework & MCP for WordPress
Version
3.4.9