Executive brief
A vulnerability in the AI Engine plugin for WordPress allows users with low-level account access to gain full administrative control over a website. The plugin, which provides chatbot and AI framework capabilities, fails to properly verify permissions when using certain authorization tokens. This could lead to a complete site takeover, data theft, or unauthorized modification of website content.
Technical details
The AI Engine plugin for WordPress (v3.4.9) contains a privilege escalation vulnerability due to improper authorization checks in the Model Context Protocol (MCP) OAuth bearer-token path. Specifically, the plugin fails to enforce WordPress capability checks when a valid OAuth token is presented, granting MCP access regardless of the user's actual role. An authenticated attacker with minimal (Subscriber+) privileges can exploit this to invoke admin-level MCP tools. This can be leveraged to escalate privileges to the Administrator role, leading to full site compromise. A changeset (3533527) indicates that a fix has been developed.
Affected products
- Jordy Meow AI Engine – The Chatbot, AI Framework & MCP for WordPress 3.4.9
Timeline
- 2026-05-17: disclosed: Vulnerability published to the CVE list.
- 2026-05-17: advisory: Wordfence published a security advisory.