{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/the-ai-engine--the-chatbot-ai-framework--mcp-for-wordpress-3.6.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-15988"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["The AI Engine – The Chatbot, AI Framework \u0026 MCP for WordPress (3.6.5)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe AI Engine - The Chatbot, AI Framework \u0026amp; MCP for WordPress plugin is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to and including 3.6.5. The vulnerability stems from missing or incorrect nonce validation within the \u003ccode\u003ereauth_for_authorize\u003c/code\u003e function. By leveraging this flaw, an unauthenticated attacker can trick a site administrator into clicking a malicious link, which triggers an unauthorized REST API call. This operation can be combined with WordPress's \u003ccode\u003e?_method=POST\u003c/code\u003e method-override feature to convert a GET request into an authenticated POST request. The impact of this exploit is severe, as it permits the creation of unauthorized administrator accounts, leading to full site compromise and persistent access for the attacker.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker crafts a malicious URL targeting a WordPress site running the vulnerable AI Engine plugin.\u003c/li\u003e\n\u003cli\u003eThe attacker delivers the link to a site administrator via social engineering (e.g., phishing).\u003c/li\u003e\n\u003cli\u003eThe administrator, while logged into the WordPress dashboard, clicks the attacker-supplied link.\u003c/li\u003e\n\u003cli\u003eThe browser initiates a request to the \u003ccode\u003ereauth_for_authorize\u003c/code\u003e endpoint, which fails to validate a nonce.\u003c/li\u003e\n\u003cli\u003eThe attacker utilizes the \u003ccode\u003e?_method=POST\u003c/code\u003e query parameter to override the HTTP method to POST.\u003c/li\u003e\n\u003cli\u003eThe REST API processes the request as an authenticated administrative action due to the administrator's active session.\u003c/li\u003e\n\u003cli\u003eThe request executes the creation of a new user account with the 'administrator' role using credentials provided by the attacker.\u003c/li\u003e\n\u003cli\u003eThe attacker authenticates as the newly created administrator to gain full control over the WordPress instance.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to full administrative compromise of the target WordPress site. An attacker gaining administrator-level access can modify site content, redirect traffic, exfiltrate sensitive data, or install further backdoors. The scope of this threat affects any organization utilizing The AI Engine plugin versions 3.6.5 or earlier, posing a significant risk to the integrity and availability of hosted web content.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following actions for your web security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the AI Engine plugin to version 3.6.6 or higher immediately to apply the vendor-provided security patch.\u003c/li\u003e\n\u003cli\u003eAudit the WordPress 'Users' table for unauthorized accounts created during the current reporting period.\u003c/li\u003e\n\u003cli\u003eDeploy web server log monitoring to identify suspicious HTTP POST requests directed toward REST API endpoints containing \u003ccode\u003ereauth_for_authorize\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eUse the provided Sigma rule to monitor for potential exploitation attempts targeting the vulnerable function.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-01T09:49:54Z","date_published":"2026-08-01T09:49:54Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wp-ai-engine-csrf/","summary":"The AI Engine WordPress plugin contains a CSRF vulnerability in the reauth_for_authorize function allowing unauthenticated attackers to create administrator accounts.","title":"CVE-2026-15988: CSRF Vulnerability in AI Engine WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-wp-ai-engine-csrf/"}],"language":"en","title":"CraftedSignal Threat Feed - The AI Engine – The Chatbot, AI Framework \u0026 MCP for WordPress (3.6.5)","version":"https://jsonfeed.org/version/1.1"}