Sceawere

Vulnerability Detail

CVE-2026-75796UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

AI Engine Privilege Escalation Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
9h ago
Vendor
Unknown
Product
AI Engine
Attack Type
CWE-269 Improper Privilege Management
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing privileged user management operations, allowing users with the Administrator role on a Multisite sub-site to take over any account on the network, including the Network Administrator's.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-08-21T07:16:25.453Z",
  "pubdate": "2026-08-21T07:16:25.453Z",
  "executiveSummary": "The AI Engine WordPress plugin before version 3.6.1 is affected by an authorization bypass vulnerability related to privileged user management operations. The vulnerability stems from a failure to properly verify whether the requesting user possesses the requisite administrative authorization to act upon a targeted user account prior to executing sensitive actions.\nThis security flaw enables authenticated malicious actors possessing the Administrator role on a WordPress Multisite sub-site to perform unauthorized account takeovers targeting any user account across the entire network. Consequently, an attacker can elevate their privileges to compromise high-privilege accounts, including the Network Administrator.\nThe risk implication is critical, as successful exploitation results in a complete compromise of the WordPress Multisite network integrity, allowing the attacker to execute arbitrary administrative actions, manipulate site configurations, and potentially execute further malicious payloads across all sub-sites within the network architecture.\nExploitation of this vulnerability requires the attacker to hold an existing Administrator role on a WordPress Multisite sub-site. No complex multi-stage exploitation requirements or social engineering tactics are necessary beyond issuing crafted requests to the vulnerable user management functionality exposed by the plugin.",
  "technicalDetails": "The root cause of this vulnerability lies in an authorization check failure within the privileged user management operations handled by the AI Engine WordPress plugin. When processing requests involving account modifications or management, the plugin fails to enforce proper capability checks or validate if the context of the requesting user grants them authority over the targeted account scope, particularly within a WordPress Multisite environment.\nThe vulnerable component resides within the user management logic of the AI Engine plugin, specifically affecting all versions prior to 3.6.1. The attack vector is network-based and exploits the lack of strict access control validation in functions responsible for handling user-related operations.\nAuthentication and privilege requirements dictate that the attacker must be authenticated and possess an Administrator role restricted to a specific WordPress Multisite sub-site. However, due to the lack of boundary enforcement between sub-site administrators and network-wide resources, these sub-site administrators can target accounts outside their administrative domain.\nThe attack flow proceeds as follows: First, the authenticated sub-site administrator initiates a request directed at the user management functionality exposed by the AI Engine plugin. Second, the plugin processes the incoming request without verifying whether the session principal holds network-level administrative privileges or explicit authorization over the targeted account. Third, the plugin executes the privileged user management operation, allowing the attacker to modify account parameters, reset credentials, or assign administrative privileges. Finally, the attacker achieves complete account takeover of the targeted user, successfully compromising high-privilege accounts such as the Network Administrator.\nThe post-exploitation impact includes total administrative control over the WordPress Multisite network, enabling the attacker to pivot across the network, inject malicious scripts, manipulate database contents, deploy backdoors, and subvert the underlying server environment."
}
CVE-2026-75796: AI Engine Privilege Escalation Vulnerability (HIGH Severity, CVSS: 7.2) - Sceawere