Skip to content
PERMISSION/PROTOCOL
Back to incident tracker

2026-09-30

HighPrimary

AI Engine Advisor Could Turn Forged Error Logs Into Administrator-Side Script Execution

CVE-2026-96561 let forged PHP error logs prompt-inject AI Engine Advisor into storing script-bearing output that executed in a WordPress administrator dashboard.

AI Engine for WordPressGovernance bypassIndirect prompt injection into an automated advisor pipeline leading to stored cross-site scriptingWordPress sites running AI Engine through version 3.8.0 with the Advisor task processing PHP error logs

What happened

In the disclosed chain, the Advisor automation incorporated an attacker-forged error-log entry into its prompt and returned JSON fields that the plugin persisted for display in the administrator dashboard.

Why it matters

Arbitrary JavaScript could execute when a WordPress administrator viewed the Advisor widget, creating confidentiality and integrity risk within the administrator session. No in-the-wild exploitation was reported.

Missing authorization check

Strict schema validation and context-appropriate output escaping before model-produced fields are persisted or rendered in privileged HTML.

Would PP block it?

A separately integrated gate could govern later consequential actions attempted from the compromised administrator session, but a receipt requirement does not make unsanitized model output safe to store or render.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-09-23

    The researcher reports the vulnerability to the vendor, according to the Wordfence CVE timeline.

  2. 2026-09-30

    The vulnerability is disclosed and the 3.8.1 changeset is identified as the remediation.

  3. 2026-10-01

    CVE-2026-96561 is published with a High CVSS 3.1 score of 7.2.

Technical breakdown

  • The REST endpoint denylist rejected exact server-parameter names, but later key canonicalization converted model_ back to model.
  • An attacker-controlled model value reached an exception message and was written unmodified to the PHP error log.
  • The Advisor task appended recent PHP error-log content verbatim to an AI prompt.
  • The model's JSON response was stored without schema or HTML sanitization, and the dashboard widget rendered title and description without output escaping.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Governance bypass. The relevant Permission Protocol gate is Data Mutation Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
Consequential downstream action boundaries outside the compromised Advisor and browser session
Still needs
The parameter-normalization bypass, forged PHP logs, prompt injection, missing output validation, persistence of script-bearing fields, and JavaScript execution in the administrator dashboard remain outside coverage. Plugin updating, strict schema validation, and context-appropriate HTML escaping are required.
Receipt required for
Later credential use, publication, data export, or configuration changes attempted from the compromised administrator session

Permission Protocol is not a sanitizer or browser execution boundary and would not by itself prevent this attacker-operated prompt-injection and stored-XSS chain.

Start small

Put the relevant gate at this action boundary.

This incident maps to Data Mutation Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop