IDOR in the WordPress AI Engine plugin's MCP surface reaches other users' media
NVD·low signal
CVE-2026-89141, published 2026-09-15, scores 6.5 and affects the AI Engine chatbot, framework and MCP plugin for WordPress through version 3.7.7 via the `mediaId` parameter, which is missing validation on a user-controlled key. It is the lowest-severity entry in this week's MCP batch but the widest-deployed: it lands MCP's trust problems on ordinary WordPress installs rather than on developer machines.