Medium severity5.9NVD Advisory· Published Jul 16, 2026· Updated Jul 16, 2026
CVE-2026-12510
CVE-2026-12510
Description
The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, allowing users with subscriber-level access to read other users' private conversations and take over their conversation records when the discussions feature is enabled.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.