What happened
In the disclosed chain, the Advisor automation incorporated an attacker-forged error-log entry into its prompt and returned JSON fields that the plugin persisted for display in the administrator dashboard.
2026-09-30
HighPrimaryCVE-2026-96561 let forged PHP error logs prompt-inject AI Engine Advisor into storing script-bearing output that executed in a WordPress administrator dashboard.
What happened
In the disclosed chain, the Advisor automation incorporated an attacker-forged error-log entry into its prompt and returned JSON fields that the plugin persisted for display in the administrator dashboard.
Why it matters
Arbitrary JavaScript could execute when a WordPress administrator viewed the Advisor widget, creating confidentiality and integrity risk within the administrator session. No in-the-wild exploitation was reported.
Missing authorization check
Strict schema validation and context-appropriate output escaping before model-produced fields are persisted or rendered in privileged HTML.
Would PP block it?
A separately integrated gate could govern later consequential actions attempted from the compromised administrator session, but a receipt requirement does not make unsanitized model output safe to store or render.
Incident analysis
2026-09-23
The researcher reports the vulnerability to the vendor, according to the Wordfence CVE timeline.
2026-09-30
The vulnerability is disclosed and the 3.8.1 changeset is identified as the remediation.
2026-10-01
CVE-2026-96561 is published with a High CVSS 3.1 score of 7.2.
Authorization boundary
This incident is categorized as Governance bypass. The relevant Permission Protocol gate is Data Mutation Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
Permission Protocol is not a sanitizer or browser execution boundary and would not by itself prevent this attacker-operated prompt-injection and stored-XSS chain.
Start small
This incident maps to Data Mutation Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.