Executive brief
The AI Engine WordPress plugin is used to integrate AI capabilities into WordPress sites, particularly on Multisite networks. A flaw in the plugin before version 3.6.1 allows a site administrator on one sub-site to take over any account on the entire network, including the network administrator's account, by bypassing authorization checks on user management operations. This could lead to complete compromise of a WordPress Multisite installation.
Technical details
The vulnerability is a broken access control / privilege escalation (CWE-269) in the AI Engine plugin's MCP (Model Context Protocol) user management tools. The plugin fails to verify that a requesting user is authorized to act on targeted accounts before executing privileged user operations such as password resets, email changes, role promotion, and user creation via REST API endpoints. An attacker with Administrator role on a Multisite sub-site can extract a REST nonce from an admin page, enable MCP on their sub-site, and then call wp_update_user and other user management tools through the /wp-json/mcp/v1/http endpoint to modify or take over any user account on the network, including the Network Administrator. The fix in version 3.6.1 adds authorization checks that return "You are not allowed to edit this user" and similar messages, preventing cross-site account manipulation.
Affected products
- Automatic AI Engine 2.8.0 to 3.6.0
Timeline
- 2026-08-19: disclosed
- 2026-08-21: patched: Fixed in version 3.6.1