Junglewise Threat Intelligence

CVE-2026-75797: Monwoo AI Engine arbitrary file read via path traversal

CVE-2026-75797 · Severity: high · CVSS 7.7 · Published 2026-08-26

Technologies: Monwoo AI Engine.

Executive brief

The AI Engine WordPress plugin contains a local file inclusion vulnerability that allows attackers with subscriber-level access (or administrative access on WordPress Multisite) to read sensitive files from the server and exfiltrate them to external services. By manipulating a URL parameter sent to the transcription feature, an attacker can bypass directory restrictions and access files outside the intended uploads folder, such as WordPress configuration files containing authentication keys and credentials. This vulnerability requires a non-default "Public API" setting to be enabled for subscriber exploitation, but affects administrators regardless of settings.

Technical details

The vulnerability is a local file inclusion (LFI) flaw in the AI Engine WordPress plugin's transcription endpoint (POST /wp-json/mwai/v1/simpleTranscribeAudio). The vulnerable get_raw_data() function maps a caller-supplied URL parameter to a local filesystem path without proper validation, allowing path traversal sequences (e.g., `../../../`) to escape the intended uploads directory. The vulnerable code reads the file content and forwards it to an external transcription service provider, enabling exfiltration. Exploitation requires either a Subscriber account with the non-default "Public API" feature enabled, or an Administrator account with no special configuration. The fix, deployed in version 3.7.2, implements lexical path resolution and rejects any attempt to read files outside the uploads directory with an error message.

Affected products

  • Monwoo AI Engine 3.3.3 through 3.7.1

Timeline

  • 2026-08-24: disclosed
  • 2026-08-26: patched: Fixed in version 3.7.2

References