What is CVE-2026-15988?
CVE-2026-15988 is a Cross-Site Request Forgery (CSRF) vulnerability in the AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin, affecting all versions up to 3.6.5. The issue stems from missing or incorrect nonce validation in the "reauth_for_authorize" function, potentially allowing unauthenticated attackers to exploit it. Users should update the plugin to the latest patched version immediately.
Azərbaycanca: CVE-2026-15988, AI Engine – The Chatbot, AI Framework & MCP for WordPress plagininin 3.6.5 versiyasına qədər olan bütün versiyalarında Cross-Site Request Forgery (CSRF) zəifliyidir. Zəiflik "reauth_for_authorize" funksiyasında nonce yoxlamasının olmaması və ya səhv olması səbəbindən baş verir və autentifikasiya olunmamış şəxslərə təsir edə bilər. İstifadəçilər plagini ən son versiyaya yeniləməli və ya təhlükəsizlik yamalarını tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
Which function in the AI Engine plugin is the source of the CVE-2026-15988 vulnerability?
The vulnerability stems from missing or incorrect nonce validation in the "reauth_for_authorize" function.
What versions of the AI Engine plugin are affected by the CVE-2026-15988 CSRF vulnerability?
All versions of the plugin up to 3.6.5 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.