Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesAI Engine

AI Engine vulnerabilities

AI Engine has 29 known vulnerabilities in this database. The most recent published record is dated 1 Oct 2026.

Known vulnerabilities
29
Active installs
90,000+
Latest version
3.8.3
Last updated
1 Oct 2026
Most recent
1 Oct 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Cross-site scripting (XSS)
CVE-2026-96561
High 7.2Up to 3.8.0Fixed in a later version (latest 3.8.3)6 d ago
Broken access control
CVE-2026-89141
Medium 6.5Up to 3.7.7Fixed in a later version (latest 3.8.3)15 Sep 2026
Path traversal
CVE-2026-75797
High 7.7Before 3.7.2Fixed in 3.7.226 Aug 2026
Broken access control
CVE-2026-75798
Medium 5.3Before 3.7.2Fixed in 3.7.226 Aug 2026
Privilege escalation
CVE-2026-75796
High 7.2Before 3.6.1Fixed in 3.6.121 Aug 2026
Broken access control
CVE-2026-16953
Medium 4.8Before 3.6.4Fixed in 3.6.48 Aug 2026
Path traversal
CVE-2026-16955
Medium 5.0Before 3.6.6Fixed in 3.6.68 Aug 2026
Sensitive data exposure
CVE-2026-16954
Medium 6.5Before 3.6.4Fixed in 3.6.46 Aug 2026
Cross-site request forgery (CSRF)
CVE-2026-15988
High 8.8Up to 3.6.5Fixed in a later version (latest 3.8.3)1 Aug 2026
Broken access control
CVE-2026-12510
Medium 5.9Before 3.5.5Fixed in 3.5.516 Jul 2026
Path traversal
CVE-2026-12511
High 8.1Before 3.5.5Fixed in 3.5.514 Jul 2026
Privilege escalation
CVE-2026-8719
High 8.8Not yet publishedCheck for an update17 May 2026
Remote code execution
CVE-2026-1400
High 7.2Up to 3.3.2Fixed in a later version (latest 3.8.3)28 Jan 2026
Server-side request forgery (SSRF)
CVE-2026-0746
Medium 6.4Up to 3.3.2Fixed in a later version (latest 3.8.3)27 Jan 2026
Server-side request forgery (SSRF)
CVE-2025-8084
Medium 6.8Up to 3.1.8Fixed in a later version (latest 3.8.3)18 Nov 2025
PHP object injection
CVE-2025-12844
High 7.1Up to 3.1.8Fixed in a later version (latest 3.8.3)13 Nov 2025
Privilege escalation
CVE-2025-11749
Critical 9.8Up to 3.1.3Fixed in a later version (latest 3.8.3)5 Nov 2025
Broken access control
CVE-2025-8268
Medium 6.5Up to 2.9.5Fixed in a later version (latest 3.8.3)3 Sep 2025
Remote code execution
CVE-2025-7847
High 8.8Not yet publishedCheck for an update31 Jul 2025
Sensitive data exposure
CVE-2025-7780
Medium 6.5Up to 2.9.4Fixed in a later version (latest 3.8.3)24 Jul 2025
Cross-site scripting (XSS)
CVE-2025-5570
Medium 5.4Before 2.8.5Fixed in 2.8.58 Jul 2025
Open redirect
CVE-2025-6238
High 8.0Not yet publishedCheck for an update4 Jul 2025
Privilege escalation
CVE-2025-5071
High 8.8Before 2.8.4Fixed in 2.8.419 Jun 2025
SQL injection
CVE-2024-10499
High 7.2Before 2.6.5Fixed in 2.6.512 Dec 2024
SQL injection
CVE-2024-6723
Medium 4.7Before 2.4.8Fixed in 2.4.813 Sep 2024
Remote code execution
CVE-2024-6451
High 7.2Before 2.4.3Fixed in 2.4.319 Aug 2024
Cross-site scripting (XSS)
CVE-2024-0378
Medium 6.5Before 2.2.1Fixed in 2.2.12 Mar 2024
Remote code execution
CVE-2024-0699
Medium 6.6Up to 2.1.4Fixed in a later version (latest 3.8.3)5 Feb 2024
Cross-site scripting (XSS)
CVE-2023-2580
Medium 4.8Before 1.6.83Fixed in 1.6.8327 Jun 2023
Read the published descriptions
CVE-2026-96561, 1 Oct 2026
The AI Engine - The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.0 This is due to a chain of missing input neutralization and output escaping across the /mwai-ui/v1/chats/submit REST endpoint, the PHP error-log parser (MeowKit_MWAI_Helpers::php_error_logs), the Advisor task (Meow_MWAI_Modules_Advisor::run_advisor), and the Advisor dashboard widget (advisor_metabox): the server-parameter denylist in chat_submit strips only exact key names such as 'model' while convert_keys() later canonicalizes 'model_' back to 'model', allowing an unauthenticated caller to place an attacker-controlled string (including CR/LF) into $query->model; final_checks() throws an Exception whose message embeds that raw string, and the non-streaming, non-admin catch branch writes it to the PHP error log unmodified - creating a forged log line that the plugin's own parser subsequently returns as recent PHP-error content; run_advisor() then appends that content verbatim to the AI prompt (indirect prompt injection - CWE-1427), the returned JSON is stored in the mwai_advisor_data option with no schema validation or HTML sanitization, and advisor_metabox() concatenates the resulting 'title' and 'description' values directly into the WordPress dashboard widget without esc_html(), wp_kses(), or equivalent escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator accesses the WordPress dashboard. CVE record
CVE-2026-89141, 15 Sep 2026
The AI Engine - The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via the 'mediaId' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to access and retrieve the transcribed contents of private audio attachments belonging to other users, including Administrators, via a supplied attachment ID. This vulnerability requires the Public API module to be enabled in the plugin settings; when disabled, the REST route is absent and the endpoint returns HTTP 404. CVE record
CVE-2026-75797, 26 Aug 2026
The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local filesystem path before reading the file and forwarding its contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature to be enabled; otherwise the same issue is reachable by an administrator, which on multisite allows a non-super subsite administrator to read the network-shared configuration and its secrets. CVE record
CVE-2026-75798, 26 Aug 2026
The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only features, relying instead on a token it hands out to anonymous visitors, allowing unauthenticated attackers to run AI queries of their own choosing against the site owner's configured provider account. CVE record
CVE-2026-75796, 21 Aug 2026
The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing privileged user management operations, allowing users with the Administrator role on a Multisite sub-site to take over any account on the network, including the Network Administrator's. CVE record
CVE-2026-16953, 8 Aug 2026
The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deletion, authorising the action solely by a client-supplied session cookie value, so an unauthenticated attacker who obtains a victim's session identifier and file reference can delete that victim's uploaded files. CVE record
CVE-2026-16955, 8 Aug 2026
The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature to be enabled; otherwise the same issue is reachable by an administrator, which on multisite allows a non-super subsite administrator to read the network-shared configuration and its secrets. CVE record
CVE-2026-16954, 6 Aug 2026
The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admin page's inline script data, allowing users with the Editor role to read the site's stored third-party API key and authentication tokens in cleartext, despite those secrets being restricted to administrators everywhere else. CVE record
CVE-2026-15988, 1 Aug 2026
The AI Engine - The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_authorize function. This makes it possible for unauthenticated attackers to create new administrator accounts with attacker-supplied credentials via a CSRF-based REST authentication bypass, granted they can trick a site administrator into performing an action such as clicking on a link. This bypass can be combined with WordPress's ?_method=POST method-override support to convert a top-navigation GET request into an authenticated POST to the REST users endpoint, requiring no existing account on the attacker's part. CVE record
CVE-2026-12510, 16 Jul 2026
The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, allowing users with subscriber-level access to read other users' private conversations and take over their conversation records when the discussions feature is enabled. CVE record
CVE-2026-12511, 14 Jul 2026
The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authenticated users with editor-level access to write attacker-controlled bytes to an arbitrary location on the server via path traversal. CVE record
CVE-2026-8719, 17 May 2026
The AI Engine - The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path, where any valid OAuth token causes MCP access to be granted without verifying administrator privileges. This makes it possible for authenticated (Subscriber+) attackers to invoke admin-level MCP tools and escalate privileges to Administrator. CVE record
CVE-2026-1400, 28 Jan 2026
The AI Engine - The Chatbot and AI Framework for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `rest_helpers_update_media_metadata` function in all versions up to, and including, 3.3.2. This makes it possible for authenticated attackers, with Editor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The attacker can upload a benign image file, then use the `update_media_metadata` endpoint to rename it to a PHP file, creating an executable PHP file in the uploads directory. CVE record
CVE-2026-0746, 27 Jan 2026
The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the 'get_audio' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services, if "Public API" is enabled in the plugin settings, and 'allow_url_fopen' is set to 'On' on the server. CVE record
CVE-2025-8084, 18 Nov 2025
The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.8 via the rest_helpers_create_images function. This makes it possible for authenticated attackers, with Editor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. On Cloud instances, this issue allows for metadata retrieving. CVE record
CVE-2025-12844, 13 Nov 2025
The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to, and including, 3.1.8 via deserialization of untrusted input in the 'rest_simpleTranscribeAudio' and 'rest_simpleVisionQuery' functions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. CVE record
CVE-2025-11749, 5 Nov 2025
The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the /mcp/v1/ REST API endpoint that exposes the 'Bearer Token' value when 'No-Auth URL' is enabled. This makes it possible for unauthenticated attackers to extract the bearer token, which can be used to gain access to a valid session and perform many actions like creating a new administrator account, leading to privilege escalation. CVE record
CVE-2025-8268, 3 Sep 2025
The AI Engine plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the rest_list and delete_files functions in all versions up to, and including, 2.9.5. This makes it possible for unauthenticated attackers to list and delete files uploaded by other users. CVE record
CVE-2025-7847, 31 Jul 2025
The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_simpleFileUpload() function in versions 2.9.3 and 2.9.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server when the REST API is enabled, which may make remote code execution possible. CVE record
CVE-2025-7780, 24 Jul 2025
The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4. The simpleTranscribeAudio endpoint fails to restrict URL schemes before calling get_audio(). This makes it possible for authenticated attackers, with Subscriber-level access and above, to read any file on the web server and exfiltrate it via the plugin’s OpenAI API integration. CVE record
CVE-2025-5570, 8 Jul 2025
The AI Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the mwai_chatbot shortcode 'id' parameter in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-6238, 4 Jul 2025
The AI Engine plugin for WordPress is vulnerable to open redirect in version 2.8.4. This is due to an insecure OAuth implementation, as the 'redirect_uri' parameter is missing validation during the authorization flow. This makes it possible for unauthenticated attackers to intercept the authorization code and obtain an access token by redirecting the user to an attacker-controlled URI. Note: OAuth is disabled, the 'Meow_MWAI_Labs_OAuth' class is not loaded in the plugin in the patched version 2.8.5. CVE record
CVE-2025-5071, 19 Jun 2025
The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'Meow_MWAI_Labs_MCP::can_access_mcp' function in versions 2.8.0 to 2.8.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to have full access to the MCP and run various commands like 'wp_create_user', 'wp_update_user' and 'wp_update_option', which can be used for privilege escalation, and 'wp_update_post', 'wp_delete_post', 'wp_update_comment' and 'wp_delete_comment', which can be used to edit and delete posts and comments. CVE record
CVE-2024-10499, 12 Dec 2024
The AI Engine WordPress plugin before 2.6.5 does not sanitize and escape a parameter from one of its RESP API endpoint before using it in a SQL statement, allowing admins to perform SQL injection attacks CVE record
CVE-2024-6723, 13 Sep 2024
The AI Engine WordPress plugin before 2.4.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when viewing chatbot discussions. CVE record
CVE-2024-6451, 19 Aug 2024
AI Engine < 2.4.3 is susceptible to remote-code-execution (RCE) via Log Poisoning. The AI Engine WordPress plugin before 2.5.1 fails to validate the file extension of "logs_path", allowing Administrators to change log filetypes from .log to .php. CVE record
CVE-2024-0378, 2 Mar 2024
The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI chat data when discussion tracking is enabled in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-0699, 5 Feb 2024
The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'add_image_from_url' function in all versions up to, and including, 2.1.4. This makes it possible for authenticated attackers, with Editor access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. CVE-2024-29100 is likely a duplicate of this issue. CVE record
CVE-2023-2580, 27 Jun 2023
The AI Engine WordPress plugin before 1.6.83 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup). CVE record

What to do if you run AI Engine

If you run AI Engine, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new AI Engine vulnerabilities

Free. We email you when a new vulnerability is published for AI Engine, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support