Junglewise Threat Intelligence

CVE-2026-27407: Meow Apps AI Engine privilege escalation in WordPress plugin

CVE-2026-27407 · Severity: high · CVSS 7.2 · Published 2026-06-15

Executive brief

The AI Engine plugin for WordPress, which integrates artificial intelligence features into websites, contains a security flaw that allows users with 'Editor' roles to gain unauthorized administrative privileges. If exploited, a trusted user with limited access could take full control of the website, potentially leading to data theft, site defacement, or complete service disruption. This vulnerability is particularly concerning for sites that rely on multiple staff members for content management.

Technical details

A privilege escalation vulnerability exists in the Meow Apps AI Engine plugin for WordPress (versions 3.4.9 and below) due to incorrect privilege assignment (CWE-266). The flaw allows a remote attacker with high-level authenticated access (specifically the 'Editor' role) to bypass intended permission restrictions and escalate their privileges to 'Administrator'. This is achieved via a network request without requiring user interaction. Successful exploitation grants the attacker full control over the WordPress environment. The issue is resolved in version 3.5.0.

Affected products

  • Meow Apps AI Engine <= 3.4.9

Timeline

  • 2025-11-06: other: Reported by Phat RiO
  • 2026-05-28: disclosed: Vulnerability disclosed by Patchstack
  • 2026-05-28: patched: Version 3.5.0 released
  • 2026-06-15: advisory: NVD published CVE-2026-27407

References

Related threats