Vulnerability  ·  2026-10-02

AI Engine WordPress plugin: forged-log prompt injection into AI context plus stored XSS in admin dashboard

VulnerabilityMedium impactGlobalCVE-2026-96561
A multi-stage chain in the AI Engine chatbot plugin: chat-submit denylist bypass → forged PHP error-log injection → indirect prompt injection into the AI prompt → unescaped dashboard rendering (stored XSS). Unauthenticated attackers can stage content that executes in the browser whenever an administrator loads the WordPress dashboard and can influence what the site's AI assistant receives as context.
It is a rare dual-class finding: an unauthenticated indirect prompt-injection path that seeds attacker text into the LLM's context via log poisoning (CWE-1427), plus a stored XSS hitting the admin. For defenders it shows WordPress AI plugins can be weaponized both to poison AI context and to hijack the admin session.
An unauthenticated caller submits a crafted chat request whose model string is canonicalized past a denylist (e.g. 'model ' → 'model'), injecting CR/LF into the query; the resulting exception message is written verbatim to the PHP error log, forging a log line that the plugin's own error-log parser later feeds into the AI prompt (indirect prompt injection, CWE-1427) and whose JSON is rendered unsanitized into the dashboard advisor widget (stored XSS on admin access).
AI Engine – The Chatbot, AI Framework & MCP for WordPress ≤ 3.8.0
Update AI Engine beyond 3.8.0 (vendor MWAI/MeowKit patched release); harden PHP error-log write access meanwhile
Patchstack plugin source referenceNVD detail
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →