CVE-2026-8719
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedThe AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path, where any valid OAuth token causes MCP access to be granted without verifying administrator privileges. This makes it possible for authenticated (Subscriber+) attackers to invoke admin-level MCP tools and escalate privileges to Administrator.
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · high confidenceThe AI Engine plugin for WordPress fails to enforce WordPress capability checks in its MCP (Model Context Protocol) OAuth bearer-token authorization mechanism. When an OAuth token is validated, the plugin grants access to MCP tools without verifying that the token holder has administrator-level privileges. This allows any authenticated user with a valid OAuth token (Subscriber role or higher) to invoke admin-level MCP tools and escalate their privileges to Administrator.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- Low
- Privileges
- Low
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Verify AI Engine plugin is installedGo to WordPress admin dashboard > Plugins, look for 'AI Engine' or search for 'AI Engine' in the plugins list. Alternatively, check the /wp-content/plugins/ directory for an 'ai-engine' folder.Affected if The AI Engine plugin is present on the WordPress site
-
Check the installed AI Engine versionIn WordPress admin > Plugins > Installed Plugins, find AI Engine and view the version number displayed. Compare this against any known affected version range for your deployment.Affected if The installed version falls within a range known to contain the vulnerability (if version information is available)
-
Confirm MCP OAuth feature is enabledNavigate to the AI Engine plugin settings (usually under Settings > AI Engine or a dedicated AI Engine menu). Look for MCP-related settings, OAuth configuration, or API settings. Check if MCP server or OAuth authentication is toggled on.Affected if MCP OAuth or MCP server functionality is enabled in the plugin settings
-
Inspect MCP endpoint accessibilityUse a browser developer tool or curl to test access to MCP endpoints (typically under /wp-json/ai-engine/mcp/* or similar paths). Attempt to access these endpoints with a low-privilege user account (Subscriber role) that has obtained an OAuth token.Affected if A Subscriber-level user with a valid OAuth token can successfully invoke admin-level MCP tools or access privileged endpoints
-
Verify capability enforcement on MCP toolsReview the AI Engine plugin source code, specifically the MCP handler files, to check if 'manage_options' or similar administrator capability checks are performed before executing privileged operations. Look for 'current_user_can' calls in MCP-related PHP files.Affected if No capability checks (or insufficient checks) are performed before granting access to administrative MCP operations
A site is affected if the AI Engine plugin is installed with MCP OAuth enabled and low-privilege users can access admin-level MCP tools without proper WordPress capability verification.
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
From vendor dataImplement proper WordPress capability checks (e.g., 'manage_options') before allowing access to administrative MCP tools, and enforce role-based access control on all MCP endpoints to ensure only administrators can invoke privileged operations.
- Consultation3.0 h
- Implementation6.0 h
- Testing4.0 h
- Review / QA2.0 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $4,224.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2026-8719 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sourcesPractitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2026-8719 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data