What is CVE-2026-16954?
A sensitive data exposure vulnerability exists in the WordPress plugin 'AI Engine' before version 3.6.4, where secret configuration values like third-party API keys are not redacted in admin page inline script data. This allows users with the Editor role to view cleartext authentication tokens, posing a risk of unauthorized access. Immediate update to version 3.6.4 or later is strongly advised.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of the WordPress 'AI Engine' plugin are affected by CVE-2026-16954?
All versions before 3.6.4 are affected.
Which privileged role is allowed to read the sensitive API keys via CVE-2026-16954?
It allows users with the Editor role to read this data.
See also6
grounded ✓NVD ↗
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.