<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:meowapps:ai_engine:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3ameowappsai_enginewordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 04:38:28 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3ameowappsai_enginewordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS via AI Engine Plugin for WordPress</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96561/</link><pubDate>Thu, 01 Oct 2026 04:38:28 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96561/</guid><description>The AI Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting, allowing unauthenticated attackers to achieve arbitrary script execution in an administrator's browser session.</description><content:encoded><![CDATA[<p>The AI Engine - The Chatbot, AI Framework &amp; MCP for WordPress plugin, versions 3.8.0 and earlier, contains a critical Stored Cross-Site Scripting (XSS) vulnerability. An unauthenticated attacker can exploit this by submitting crafted input to the '/mwai-ui/v1/chats/submit' REST endpoint. The vulnerability arises from an insufficient denylist in the plugin's key processing logic, which allows attackers to inject malicious strings, including carriage returns and line feeds, into the PHP error log.</p>
<p>The plugin's internal Advisor module parses these tainted log files and stores the data into the WordPress 'mwai_advisor_data' option without performing HTML sanitization or schema validation. When an administrator views the WordPress dashboard, the 'advisor_metabox' function retrieves this stored, malicious content and renders it directly into the dashboard widget. Because the output is not escaped via 'esc_html()' or 'wp_kses()', the injected payload executes within the context of the administrator's session. This flaw could be leveraged to perform unauthorized administrative actions or exfiltrate session data.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Unauthenticated attacker sends a malicious HTTP POST request to the '/mwai-ui/v1/chats/submit' REST endpoint.</li>
<li>Attacker crafts input using key canonicalization bypasses (e.g., 'model_' instead of 'model') to inject malicious strings containing script tags.</li>
<li>The plugin generates an Exception containing the raw malicious string and writes it to the server's PHP error log.</li>
<li>The 'MeowKit_MWAI_Helpers::php_error_logs' parser reads the forged log lines as valid recent errors.</li>
<li>The 'Meow_MWAI_Modules_Advisor::run_advisor' module appends the malicious content to the AI prompt and saves it to the database 'mwai_advisor_data' option.</li>
<li>An administrator accesses the WordPress dashboard, triggering the 'advisor_metabox' widget to display the stored data.</li>
<li>The widget renders the injected script directly into the admin page, executing in the administrator's browser.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in arbitrary script execution in the administrator's browser context. An attacker could potentially perform actions such as creating new administrative accounts, modifying site settings, or stealing session cookies, leading to full site compromise. This vulnerability affects any WordPress installation running the AI Engine plugin versions 3.8.0 or earlier.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize updating the AI Engine - The Chatbot, AI Framework &amp; MCP for WordPress plugin to the latest version. Monitor web server access logs for anomalous POST requests directed at the '/mwai-ui/v1/chats/submit' path. Implement Web Application Firewall (WAF) rules to inspect and filter REST API requests for suspicious characters (such as '&lt;script&gt;' tags or event handlers) targeting this specific endpoint.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>xss</category><category>injection</category><category>webserver</category></item></channel></rss>