CVE-2026-15988Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-01); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-01: 2Mentions · 2026-08-02: 1Patch / Workaround · 2026-08-01: 1Patch / Workaround · 2026-08-02: 1Technical Details · 2026-08-01: 2Technical Details · 2026-08-02: 108-0108-02
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-08-012
Disclosure2
2026-08-021
Patch1
Full discourse3 posts
  • Mohi@disismohi
    Patch

    AI Engine WordPress plugin (<=3.6.5): click a link, attacker gets admin access. No auth required. CVE-2026-15988, CVSS 8.8, patched in 3.6.6.

    Post summary

    CVE-2026-15988 in the AI Engine WordPress plugin lets unauthenticated users gain admin access, but the patch (v3.6.6) is already available.

    1000060
    73 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨HIGH - WordPress AI Engine CSRF to REST Auth Bypass Admin Creation (CVE-2026-15988) AI Engine – The Chatbot, AI Framework & MCP for WordPress lacks proper nonce validation in reauth_for_authorize, enabling CSRF. An unauth attacker can lure an admin to a crafted link, abuse WordPress ?_method=POST to convert GET navigation into an authenticated POST to /wp-json/wp/v2/users, creating a new administrator with attacker-controlled creds. 👉Affected: AI Engine – The Chatbot, AI Framework & MCP for WordPress <= 3.6.5

    Post summary

    The post discloses a CSRF flaw in WordPress AI Engine that enables an unauthenticated attacker to create a new administrator via the REST API, with no PoC, exploit, or patch mentioned.

    00010117
    278 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-15988 - CSRF in AI Engine WordPress plugin enables attacker to create admin accounts via REST auth bypass. CVSS 8.8. Unpatched - disable plugin now. #CVE #WordPress #infosec #cvealert #splunk #yara #sigma #100daysofcybersecurity #cybersecurityawareness #cybersecuritynews #cybersecuritytips #developer #developers #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #python https://www.valtersit.com/cve/CVE-2026-15988

    Post summary

    CVE-2026-15988 is a CSRF vulnerability in the AI Engine WordPress plugin that lets attackers create admin accounts through a REST auth bypass; users are urged to disable the plugin until a patch is available.

    0000057
    978 followersView on X

Explore more