CVE-2026-12510
MEDIUMAI Engine < 3.5.5 - Subscriber+Chatbot Discussion Disclosure and Takeover via IDOR
Title source: cnaDescription
The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, allowing users with subscriber-level access to read other users' private conversations and take over their conversation records when the discussions feature is enabled.
References (1)
Core 1
Core References
Exploit exploit
vdb-entry
technical-description
https://wpscan.com/vulnerability/b7825c8a-1817-4a17-b641-076e48ac7c2e/
Scores
CVSS v3
5.9
EPSS
0.0014
EPSS Percentile
4.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-639
Status
published
Products (1)
None/AI Engine
< 3.5.5
Published
Jul 16, 2026
Tracked Since
Jul 16, 2026