CVE-2026-16953Disclosure

LOWCVSS 4.8 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deletion, authorising the action solely by a client-supplied session cookie value, so an unauthenticated attacker who obtains a victim's session identifier and file reference can delete that victim's uploaded files.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-08: 3Technical Details · 2026-08-08: 308-08
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-16953 The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deletion, authorising the action solely by a client-… https://www.cve.org/CVERecord?id=CVE-2026-16953 ----- Traducción: CVE-2026-16953 El … http://infoflow.cloud`

    Post summary

    This post discloses CVE-2026-16953, a flaw in the AI Engine WordPress plugin that fails to verify ownership of guest‑uploaded chatbot files before deletion, potentially permitting unauthorized deletions.

    0000044
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-16953 The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deletion, authorising the action solely by a client-… https://www.cve.org/CVERecord?id=CVE-2026-16953

    Post summary

    This post simply provides a brief disclosure of the CVE’s core issue, without mention of PoC, exploit code, active attacks, patches, or debunking.

    000001.9K
    57.9K followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    🤖 AI Engine WordPress flaw allows chatbot-file deletion CVE-2026-16953 AI Engine versions before 3.6.4 fail to correctly verify ownership of guest-uploaded chatbot files. An unauthenticated attacker who obtains the necessary session identifier and file reference could delete another user's uploaded files. 🔎 Source: WPScan / CVE #WordPress #AISecurity #CVE #CyberSecurity

    Post summary

    The post announces CVE-2026-16953, detailing an ownership check failure in AI Engine before v3.6.4 that lets attackers delete files without authentication, but provides no PoC, exploit, patch info or evidence of active attacks.

    0000036
    34 followersView on X

Explore more