cleantalk
Vulnerabilities and Security Researches

AI Engine, CVE-2026-12511

CVE, Research URL

CVE-2026-12511

Application

AI Engine

Published on
Jul 14, 2026
Research Description
The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authenticated users with editor-level access to write attacker-controlled bytes to an arbitrary location on the server via path traversal.
Affected versions
max 3.5.5.
Status
vulnerable