CVE-2026-12511
The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing
CVSS
8.1
High
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Published: Jul 14, 2026 · Last modified: Jul 14, 2026
0.3%EPSS · 30 days0.3%
2026-08-102026-09-07
The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authenticated users with editor-level access to write attacker-controlled bytes to an arbitrary location on the server via path traversal.
No related CVEs by CWE or product.