---
id: CVE-2026-89141
title: >-
  The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for
  WordPress is vulnerable to Insecure Direct Object Reference in all versions up
  to, and including, 3.7.7 via the 'mediaId' parameter due to missing validation
  on a u…
summary: >-
  The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for
  WordPress is vulnerable to Insecure Direct Object Reference in all versions up
  to, and including, 3.7.7 via the 'mediaId' parameter due to missing validation
  on a u…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-639
vendor: tigroumeow
product: 'AI Engine – The Chatbot, AI Framework & MCP for WordPress'
affected:
  - ai_engine_the_chatbot_ai_framework_mcp_for_wordpress <= 3.7.7
published: '2026-09-15'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T14:37:14.523'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89141'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/ai-engine/tags/3.7.7/classes/api.php#L1168
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/ai-engine/tags/3.7.7/classes/api.php#L637
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/ai-engine/tags/3.7.7/classes/api.php#L663
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/ai-engine/tags/3.7.7/classes/core.php#L253
    label: security@wordfence.com
  - url: 'https://plugins.trac.wordpress.org/changeset/3693379'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/2cb2ad5d-aa92-4186-aaae-45dde4a52f30?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T13:25:16.438622Z'
epss: 0.00272
epssPercentile: 0.1984
ingestedAt: '2026-09-15T07:33:29.276Z'
---

## Overview

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via the 'mediaId' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to access and retrieve the transcribed contents of private audio attachments belonging to other users, including Administrators, via a supplied attachment ID. This vulnerability requires the Public API module to be enabled in the plugin settings; when disabled, the REST route is absent and the endpoint returns HTTP 404.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
