AI Engine, CVE-2026-12511
- CVE, Research URL
- Home page URL
- Application
- Published on
- Jul 14, 2026
- Research Description
- The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authenticated users with editor-level access to write attacker-controlled bytes to an arbitrary location on the server via path traversal.
- Affected versions
-
max 3.5.5.
- Status
-
vulnerable