WordPress Plugin Vulnerabilities

AI Engine 2.8.0 - 3.6.0 - Admin+ Multisite Network Administrator Account Takeover via MCP User Tools

Description

The plugin does not verify that the requesting user is authorized to act on the targeted account before performing privileged user management operations, allowing users with the Administrator role on a Multisite sub-site to take over any account on the network, including the Network Administrator's.

Proof of Concept

Affects Plugins

Fixed in 3.6.1

References

Classification

Miscellaneous

Original Researcher
Charles Vosburgh
Submitter
Charles Vosburgh
Verified
Yes

Timeline

Publicly Published
2026-08-19 (about 2 days ago)
Added
2026-08-19 (about 1 day ago)
Last Updated
2026-08-19 (about 1 day ago)

Other