---
id: CVE-2026-16955
title: >-
  The AI Engine  WordPress plugin before 3.6.6 does not confine a
  caller-supplied file path before reading it and forwarding the contents to an
  external service, allowing users with a subscriber-level account to read
  arbitrary files from t…
summary: >-
  The AI Engine  WordPress plugin before 3.6.6 does not confine a
  caller-supplied file path before reading it and forwarding the contents to an
  external service, allowing users with a subscriber-level account to read
  arbitrary files from t…
severity: none
published: '2026-08-08'
updated: '2026-08-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16955'
references:
  - url: 'https://wpscan.com/vulnerability/1b413d84-61c7-4e19-a693-312d74f618ff/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00342
epssPercentile: 0.24877
ingestedAt: '2026-08-09T03:32:40.688Z'
---

## Overview

The AI Engine  WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature to be enabled; otherwise the same issue is reachable by an administrator, which on multisite allows a non-super subsite administrator to read the network-shared configuration and its secrets.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
