Skip to content
Threat Feed
high advisory

Stored XSS via AI Engine Plugin for WordPress

The AI Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting, allowing unauthenticated attackers to achieve arbitrary script execution in an administrator's browser session.

CVE search metadata

CVE search record: CVE-2026-96561. Severity: high. CVSS: 7.2. KEV: no. Product: The AI Engine – The Chatbot, AI Framework & MCP for WordPress (<= 3.8.0). Brief: Stored XSS via AI Engine Plugin for WordPress. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96561/

The AI Engine - The Chatbot, AI Framework & MCP for WordPress plugin, versions 3.8.0 and earlier, contains a critical Stored Cross-Site Scripting (XSS) vulnerability. An unauthenticated attacker can exploit this by submitting crafted input to the '/mwai-ui/v1/chats/submit' REST endpoint. The vulnerability arises from an insufficient denylist in the plugin's key processing logic, which allows attackers to inject malicious strings, including carriage returns and line feeds, into the PHP error log.

The plugin's internal Advisor module parses these tainted log files and stores the data into the WordPress 'mwai_advisor_data' option without performing HTML sanitization or schema validation. When an administrator views the WordPress dashboard, the 'advisor_metabox' function retrieves this stored, malicious content and renders it directly into the dashboard widget. Because the output is not escaped via 'esc_html()' or 'wp_kses()', the injected payload executes within the context of the administrator's session. This flaw could be leveraged to perform unauthorized administrative actions or exfiltrate session data.

Attack Chain

  1. Unauthenticated attacker sends a malicious HTTP POST request to the '/mwai-ui/v1/chats/submit' REST endpoint.
  2. Attacker crafts input using key canonicalization bypasses (e.g., 'model_' instead of 'model') to inject malicious strings containing script tags.
  3. The plugin generates an Exception containing the raw malicious string and writes it to the server's PHP error log.
  4. The 'MeowKit_MWAI_Helpers::php_error_logs' parser reads the forged log lines as valid recent errors.
  5. The 'Meow_MWAI_Modules_Advisor::run_advisor' module appends the malicious content to the AI prompt and saves it to the database 'mwai_advisor_data' option.
  6. An administrator accesses the WordPress dashboard, triggering the 'advisor_metabox' widget to display the stored data.
  7. The widget renders the injected script directly into the admin page, executing in the administrator's browser.

Impact

Successful exploitation results in arbitrary script execution in the administrator's browser context. An attacker could potentially perform actions such as creating new administrative accounts, modifying site settings, or stealing session cookies, leading to full site compromise. This vulnerability affects any WordPress installation running the AI Engine plugin versions 3.8.0 or earlier.

Recommendation

Prioritize updating the AI Engine - The Chatbot, AI Framework & MCP for WordPress plugin to the latest version. Monitor web server access logs for anomalous POST requests directed at the '/mwai-ui/v1/chats/submit' path. Implement Web Application Firewall (WAF) rules to inspect and filter REST API requests for suspicious characters (such as '<script>' tags or event handlers) targeting this specific endpoint.


Immediate actions

Update AI Engine plugin to the latest version patched for CVE-2026-96561.

IT Operations 24h

Threat Hunt

Search webserver access logs for POST requests to /mwai-ui/v1/chats/submit containing suspicious payloads.

T1190 high high confidence hunt now

Data: webserver_logs

Mitigations

Update plugin to version > 3.8.0.

immediate IT Operations

CVE-2026-96561