Vulnerabilities and security researches forai-engine ai-engine
Direction: ascendingJun 07, 2024
AI Engine # 79caac2c3bd13a2edc1a48183f8fe12c9f7ff876
- CVE, Research URL
- Home page URL
- Application
- Date
- May 19, 2023
- Research Description
- AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 1.6.83 AI Engine: ChatGPT Chatbot, Content Generator, GPT 3 & 4, Ultra-Customizable <= 1.6.82 - Authenticated (Admin+) Stored Cross-Site Scripting The AI Engine: ChatGPT Chatbot, Content Generator, GPT 3 & 4, Ultra-Customizable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in versions up to, and including, 1.6.82 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
- Affected versions
-
max 1.6.83.
- Status
-
vulnerable
AI Engine # CVE-2024-0699
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 06, 2024
- Research Description
- The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'add_image_from_url' function in all versions up to, and including, 2.1.4. This makes it possible for authenticated attackers, with Editor access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. CVE-2024-29100 is likely a duplicate of this issue.
- Affected versions
-
max 2.1.5.
- Status
-
vulnerable
AI Engine # CVE-2023-51409
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 12, 2024
- Research Description
- Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 1.9.98.
- Affected versions
-
max 1.9.99.
- Status
-
vulnerable
AI Engine # CVE-2024-0378
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 02, 2024
- Research Description
- The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI chat data when discussion tracking is enabled in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 2.2.1.
- Status
-
vulnerable
AI Engine # CVE-2024-29100
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 28, 2024
- Research Description
- Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.
- Affected versions
-
max 2.1.5.
- Status
-
vulnerable
AI Engine # CVE-2024-29090
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 28, 2024
- Research Description
- Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.
- Affected versions
-
max 2.1.5.
- Status
-
vulnerable
AI Engine # CVE-2023-2580
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 27, 2023
- Research Description
- The AI Engine WordPress plugin before 1.6.83 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).
- Affected versions
-
max 1.6.83.
- Status
-
vulnerable
AI Engine # CVE-2024-34440
- CVE, Research URL
- Home page URL
- Application
- Date
- May 14, 2024
- Research Description
- Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.2.63.
- Affected versions
-
max 2.2.70.
- Status
-
vulnerable
Jul 26, 2024
AI Engine # CVE-2024-38791
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 02, 2024
- Research Description
- Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot allows Server Side Request Forgery.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.4.7.
- Affected versions
-
max 2.4.8.
- Status
-
vulnerable
Aug 21, 2024
AI Engine # CVE-2024-6451
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 19, 2024
- Research Description
- AI Engine < 2.4.3 is susceptible to remote-code-execution (RCE) via Log Poisoning. The AI Engine WordPress plugin before 2.5.1 fails to validate the file extension of "logs_path", allowing Administrators to change log filetypes from .log to .php.
- Affected versions
-
max 2.5.1.
- Status
-
vulnerable
Sep 15, 2024
AI Engine # CVE-2024-6723
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 13, 2024
- Research Description
- The AI Engine WordPress plugin before 2.4.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when viewing chatbot discussions.
- Affected versions
-
max 2.4.8.
- Status
-
vulnerable
Dec 12, 2024
AI Engine # CVE-2024-10499
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 12, 2024
- Research Description
- The AI Engine WordPress plugin before 2.6.5 does not sanitize and escape a parameter from one of its RESP API endpoint before using it in a SQL statement, allowing admins to perform SQL injection attacks
- Affected versions
-
max 2.6.5.
- Status
-
vulnerable
May 06, 2025
AI Engine # CVE-2023-4253
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 04, 2023
- Research Description
- The AI ChatBot WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected versions
-
max 1.1.1.
- Status
-
vulnerable
Jul 02, 2025
AI Engine # CVE-2025-5071
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 19, 2025
- Research Description
- The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'Meow_MWAI_Labs_MCP::can_access_mcp' function in versions 2.8.0 to 2.8.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to have full access to the MCP and run various commands like 'wp_create_user', 'wp_update_user' and 'wp_update_option', which can be used for privilege escalation, and 'wp_update_post', 'wp_delete_post', 'wp_update_comment' and 'wp_delete_comment', which can be used to edit and delete posts and comments.
- Affected versions
-
Min 2.8.0, max 2.8.4.
- Status
-
vulnerable
Jul 05, 2025
AI Engine # CVE-2025-6238
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 04, 2025
- Research Description
- The AI Engine plugin for WordPress is vulnerable to open redirect in version 2.8.4. This is due to an insecure OAuth implementation, as the 'redirect_uri' parameter is missing validation during the authorization flow. This makes it possible for unauthenticated attackers to intercept the authorization code and obtain an access token by redirecting the user to an attacker-controlled URI. Note: OAuth is disabled, the 'Meow_MWAI_Labs_OAuth' class is not loaded in the plugin in the patched version 2.8.5.
- Affected versions
-
max 2.8.5.
- Status
-
vulnerable
Jul 09, 2025
AI Engine # CVE-2025-5570
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 08, 2025
- Research Description
- The AI Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the mwai_chatbot shortcode 'id' parameter in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 2.8.5.
- Status
-
vulnerable
Jul 25, 2025
AI Engine # CVE-2025-7780
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 24, 2025
- Research Description
- The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4. The simpleTranscribeAudio endpoint fails to restrict URL schemes before calling get_audio(). This makes it possible for authenticated attackers, with Subscriber-level access and above, to read any file on the web server and exfiltrate it via the plugin’s OpenAI API integration.
- Affected versions
-
max 2.9.5.
- Status
-
vulnerable
Aug 01, 2025
AI Engine # CVE-2025-7847
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 31, 2025
- Research Description
- The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_simpleFileUpload() function in versions 2.9.3 and 2.9.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server when the REST API is enabled, which may make remote code execution possible.
- Affected versions
-
Min 2.9.3, max 2.9.5.
- Status
-
vulnerable
Aug 06, 2025
AI Engine # PSC-2025-64580
- PSC, Research URL
- Home page URL
- Application
- Date
- Aug 06, 2025
- Research Description
- AI Engine is an advanced WordPress plugin designed to bridge the power of modern AI models (like GPT-4.1, Claude, Gemini, o4, and others) with the flexibility and usability of WordPress. Whether you’re aiming to build custom chatbots, generate content, translate articles, or automate content workflows, AI Engine provides a powerful and secure solution—all from within the WordPress dashboard.
- Affected versions
-
Min 3.7.0, max 3.7.0.
- Status
-
SAFE & CERTIFIED
Nov 10, 2025
AI Engine # CVE-2025-11749
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 05, 2025
- Research Description
- The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the /mcp/v1/ REST API endpoint that exposes the 'Bearer Token' value when 'No-Auth URL' is enabled. This makes it possible for unauthenticated attackers to extract the bearer token, which can be used to gain access to a valid session and perform many actions like creating a new administrator account, leading to privilege escalation.
- Affected versions
-
max 3.1.4.
- Status
-
vulnerable
Dec 11, 2025
AI Engine # CVE-2025-12844
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 13, 2025
- Research Description
- The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to, and including, 3.1.8 via deserialization of untrusted input in the 'rest_simpleTranscribeAudio' and 'rest_simpleVisionQuery' functions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
- Affected versions
-
max 3.1.9.
- Status
-
vulnerable
Apr 15, 2026
AI Engine # CVE-2026-1400
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 28, 2026
- Research Description
- The AI Engine – The Chatbot and AI Framework for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `rest_helpers_update_media_metadata` function in all versions up to, and including, 3.3.2. This makes it possible for authenticated attackers, with Editor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The attacker can upload a benign image file, then use the `update_media_metadata` endpoint to rename it to a PHP file, creating an executable PHP file in the uploads directory.
- Affected versions
-
max 3.3.3.
- Status
-
vulnerable
AI Engine # CVE-2026-0746
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 28, 2026
- Research Description
- The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the 'get_audio' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services, if "Public API" is enabled in the plugin settings, and 'allow_url_fopen' is set to 'On' on the server.
- Affected versions
-
max 3.3.3.
- Status
-
vulnerable
Apr 24, 2026
AI Engine # CVE-2025-8268
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 04, 2025
- Research Description
- The AI Engine plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the rest_list and delete_files functions in all versions up to, and including, 2.9.5. This makes it possible for unauthenticated attackers to list and delete files uploaded by other users.
- Affected versions
-
max 2.9.6.
- Status
-
vulnerable
May 20, 2026
AI Engine # CVE-2026-8719
- CVE, Research URL
- Home page URL
- Application
- Date
- May 17, 2026
- Research Description
- The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path, where any valid OAuth token causes MCP access to be granted without verifying administrator privileges. This makes it possible for authenticated (Subscriber+) attackers to invoke admin-level MCP tools and escalate privileges to Administrator.
- Affected versions
-
max 3.5.0.
- Status
-
vulnerable
AI Engine # CVE-2025-8084
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 18, 2025
- Research Description
- The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.8 via the rest_helpers_create_images function. This makes it possible for authenticated attackers, with Editor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. On Cloud instances, this issue allows for metadata retrieving.
- Affected versions
-
max 3.1.9.
- Status
-
vulnerable
Jun 04, 2026
AI Engine # CVE-2026-27407
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 16, 2026
- Research Description
- Editor Privilege Escalation in AI Engine <= 3.4.9 versions.
- Affected versions
-
max 3.5.0.
- Status
-
vulnerable
Jun 14, 2026
AI Engine # CVE-2026-23802
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 05, 2026
- Research Description
- Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine ai-engine allows Using Malicious Files.This issue affects AI Engine: from n/a through <= 3.3.2.
- Affected versions
-
max 3.3.3.
- Status
-
vulnerable
Jun 16, 2026
AI Engine # 21a6533cf7116e730acb86ec7750d660dce20694
- CVE, Research URL
- Home page URL
- Application
- Date
- May 19, 2023
- Research Description
- AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 1.6.83 WordPress AI Engine: ChatGPT Chatbot Plugin < 1.6.83 is vulnerable to Cross Site Scripting (XSS) Update the WordPress AI Engine: ChatGPT Chatbot plugin to the latest available version (at least 1.6.83). WPScanTeam discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress AI Engine: ChatGPT Chatbot Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.6.83.
- Affected versions
-
max 1.6.83.
- Status
-
vulnerable
AI Engine # 7f5449dc8d09819a2b897628d4142dd44c0ac3e9
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 18, 2024
- Research Description
- AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 2.1.5 AI Engine <= 2.1.4 - Authenticated(Editor+) Arbitrary File Upload via add_image_from_url The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'add_image_from_url' function in all versions up to, and including, 2.1.4. This makes it possible for authenticated attackers, with Editor access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. CVE-2024-29100 is likely a duplicate of this issue.
- Affected versions
-
max 2.1.5.
- Status
-
vulnerable
Jul 16, 2026
AI Engine # CVE-2026-12511
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 14, 2026
- Research Description
- The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authenticated users with editor-level access to write attacker-controlled bytes to an arbitrary location on the server via path traversal.
- Affected versions
-
max 3.5.5.
- Status
-
vulnerable
Aug 02, 2026
AI Engine # CVE-2026-15988
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 01, 2026
- Research Description
- The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_authorize function. This makes it possible for unauthenticated attackers to create new administrator accounts with attacker-supplied credentials via a CSRF-based REST authentication bypass, granted they can trick a site administrator into performing an action such as clicking on a link. This bypass can be combined with WordPress's ?_method=POST method-override support to convert a top-navigation GET request into an authenticated POST to the REST users endpoint, requiring no existing account on the attacker's part.
- Affected versions
-
max 3.6.6.
- Status
-
vulnerable
Aug 06, 2026
AI Engine # CVE-2026-65545
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.6.9 CVE-2026-65545
- Affected versions
-
max 3.6.9.
- Status
-
vulnerable
Aug 22, 2026
AI Engine # CVE-2026-75796
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 21, 2026
- Research Description
- The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing privileged user management operations, allowing users with the Administrator role on a Multisite sub-site to take over any account on the network, including the Network Administrator's.
- Affected versions
-
max 3.6.1.
- Status
-
vulnerable