PT-2026-79309 · WordPress · Ai Engine
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AI Engine versions prior to 3.6.1
Description
Insufficient authorization verification during privileged user management operations allows a user with the Administrator role on a Multisite sub-site to take over any account within the network, including the Network Administrator account.
Recommendations
Update AI Engine to version 3.6.1 or later.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ai Engine