CVE-2026-12510

The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, allowing users with subscriber-level access to read other users' private conversations and take over their conversation records when the discussions feature is enabled.
Configurations

No configuration.

History

16 Jul 2026, 16:18

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9
CWE CWE-639

16 Jul 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-16 07:16

Updated : 2026-07-16 16:18


NVD link : CVE-2026-12510

Mitre link : CVE-2026-12510

CVE.ORG link : CVE-2026-12510


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key