What is CVE-2026-16953?
A critical vulnerability exists in the AI Engine WordPress plugin before version 3.6.4. An unauthenticated attacker can delete guest-uploaded chatbot files by exploiting insufficient ownership verification, using only a victim's session cookie and file reference. Users must update to version 3.6.4 or newer immediately.
Azərbaycanca: AI Engine WordPress plaginində (3.6.4-dən əvvəlki versiyalarda) kritik zəiflik aşkarlanıb. Təcavüzkar qurbanın sessiya kukunu ələ keçirərək, qonaq tərəfindən yüklənmiş chatbot fayllarını icazəsiz silə bilər. İstifadəçilər dərhal plagini 3.6.4 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the AI Engine plugin are affected by CVE-2026-16953?
This vulnerability affects all versions of the AI Engine WordPress plugin prior to 3.6.4.
What does an attacker need to exploit this vulnerability?
An unauthenticated attacker can delete guest-uploaded chatbot files by exploiting insufficient ownership verification, using only a victim's session cookie and file reference.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.