🚨HIGH - WordPress AI Engine CSRF to REST Auth Bypass Admin Creation (CVE-2026-15988)
AI Engine – The Chatbot, AI Framework & MCP for WordPress lacks proper nonce validation in reauth_for_authorize, enabling CSRF. An unauth attacker can lure an admin to a crafted link, abuse WordPress ?_method=POST to convert GET navigation into an authenticated POST to /wp-json/wp/v2/users, creating a new administrator with attacker-controlled creds.
👉Affected: AI Engine – The Chatbot, AI Framework & MCP for WordPress <= 3.6.5
Post summary
The post discloses a CSRF flaw in WordPress AI Engine that enables an unauthenticated attacker to create a new administrator via the REST API, with no PoC, exploit, or patch mentioned.
CVE-2026-15988 - CSRF in AI Engine WordPress plugin enables attacker to create admin accounts via REST auth bypass. CVSS 8.8. Unpatched - disable plugin now. #CVE#WordPress#infosec#cvealert#splunk#yara#sigma#100daysofcybersecurity#cybersecurityawareness#cybersecuritynews#cybersecuritytips#developer#developers#git#github#gitlab#redteam#blueteam#ethicalhacker#ethicalhacking#python https://www.valtersit.com/cve/CVE-2026-15988
Post summary
CVE-2026-15988 is a CSRF vulnerability in the AI Engine WordPress plugin that lets attackers create admin accounts through a REST auth bypass; users are urged to disable the plugin until a patch is available.