PatchSiren cyber security CVE debrief
CVE-2026-8719 tigroumeow CVE debrief
CVE-2026-8719 is a privilege-escalation flaw in the AI Engine WordPress plugin’s MCP OAuth authorization flow. The issue stems from missing WordPress capability enforcement: if a requester presents any valid OAuth bearer token, MCP access is granted without confirming administrator-level privileges. In practical terms, authenticated users at Subscriber level or above may be able to invoke admin-level MCP tools and elevate themselves to Administrator. The CVSS score is 8.8 (High).
- Vendor
- tigroumeow
- Product
- AI Engine – The Chatbot, AI Framework & MCP for WordPress
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-17
- Original CVE updated
- 2026-05-18
- Advisory published
- 2026-05-17
- Advisory updated
- 2026-05-18
Who should care
WordPress site owners and administrators running the AI Engine plugin, especially environments that allow Subscriber+ accounts or expose MCP/OAuth functionality. Security teams should also care if the site uses the plugin for automation or exposes admin-like tools through MCP.
Technical summary
NVD records the vulnerability as CVE-2026-8719 with CVSS v3.1 vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H and weakness classification CWE-269. The Wordfence-referenced description indicates that in AI Engine 3.4.9, the MCP OAuth bearer-token authorization path did not enforce the WordPress capability check required to distinguish ordinary authenticated users from administrators. Because access was granted on the basis of a valid OAuth token alone, an authenticated lower-privilege user could reach MCP tools intended for admins and escalate privileges.
Defensive priority
High. This is an authenticated privilege-escalation issue with direct administrative impact, low attack complexity, and no user interaction required. If the plugin is present and MCP/OAuth features are enabled, remediation should be treated as urgent.
Recommended defensive actions
- Update the AI Engine plugin to a version that includes the capability-enforcement fix referenced by the WordPress changeset.
- Review any authenticated user roles on affected WordPress sites, especially Subscriber and other low-privilege accounts.
- Temporarily disable MCP or OAuth access paths if patching cannot be completed immediately.
- Audit WordPress administrative accounts and recent privilege changes for signs of unauthorized escalation.
- Check plugin logs and site activity for unexpected MCP tool usage from non-administrative users.
Evidence notes
Primary evidence comes from the NVD record for CVE-2026-8719 and the Wordfence-referenced sources listed there. The NVD entry identifies the weakness as CWE-269 and includes the vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The referenced WordPress plugin changeset and Wordfence advisory support the description that missing capability enforcement in the MCP OAuth bearer-token path allows authenticated users to gain elevated access.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8719 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8719
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8719 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8719
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/changeset/3533527/ai-engine
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.