AI Engine – The Chatbot, AI Framework & MCP for WordPress <= 3.6.0 - Authenticated (Administrator+) Privilege Escalation
medium
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.0. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for authenticated attackers, with administ...
- CVSS:
- 4.7
- Affected:
- up to 3.6.0
- Fixed in:
- 3.6.1
- Disclosed:
- Aug 24, 2026
CVE-2026-75796 on NVD →
AI Engine <= 3.6.5 - Authenticated (Subscriber+) Arbitrary File Read
medium
The AI Engine plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 3.6.5. This is due to insufficient validation of a user supplied path. This makes it possible for authenticated attackers, with subscriber-level access and above, to read arbitrary files on the server, including se...
- CVSS:
- 6.5
- Affected:
- up to 3.6.5
- Fixed in:
- 3.6.6
- Disclosed:
- Aug 3, 2026
CVE-2026-16955 on NVD →
AI Engine <= 3.6.3 - Insecure Direct Object Reference to Unauthenticated Cross-Session Chatbot File Deletion
medium
The AI Engine plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.6.3. This is due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.6.3
- Fixed in:
- 3.6.4
- Disclosed:
- Aug 3, 2026
CVE-2026-16953 on NVD →
AI Engine <= 3.6.5 - Cross-Site Request Forgery to Privilege Escalation via REQUEST_URI Substring Match
high
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_authorize function. This makes it possible for unauthenticated attackers to cr...
- CVSS:
- 8.8
- Affected:
- up to 3.6.5
- Fixed in:
- 3.6.6
- Disclosed:
- Jul 31, 2026
CVE-2026-15988 on NVD →
AI Engine <= 3.6.3 - Authenticated (Editor+) Information Exposure
low
The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.6.3. This makes it possible for authenticated attackers, with editor-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 2.7
- Affected:
- up to 3.6.3
- Fixed in:
- 3.6.4
- Disclosed:
- Jul 30, 2026
CVE-2026-16954 on NVD →
AI Engine – The Chatbot, AI Framework & MCP for WordPress <= 3.6.8 - Unauthenticated Stored Cross-Site Scripting
high
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...
- CVSS:
- 7.2
- Affected:
- up to 3.6.8
- Fixed in:
- 3.6.9
- Disclosed:
- Jul 28, 2026
CVE-2026-65545 on NVD →
AI Engine <= 3.5.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Chatbot Discussion Disclosure
medium
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.5.4 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Custom-level access and above, to...
- CVSS:
- 4.3
- Affected:
- up to 3.5.4
- Fixed in:
- 3.5.5
- Disclosed:
- Jun 25, 2026
CVE-2026-12510 on NVD →
AI Engine <= 3.5.4 - Authenticated (Editor+) Arbitrary File Write
high
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with Editor-level access and above, to write to arbitrary files on the server, which can make remote co...
- CVSS:
- 7.2
- Affected:
- up to 3.5.4
- Fixed in:
- 3.5.5
- Disclosed:
- Jun 23, 2026
CVE-2026-12511 on NVD →
AI Engine – The Chatbot, AI Framework & MCP for WordPress <= 3.4.9 - Authenticated (Editor+) Privilege Escalation
high
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.4.9. This makes it possible for authenticated attackers, with Editor-level access and above, to elevate their privileges.
- CVSS:
- 7.2
- Affected:
- up to 3.4.9
- Fixed in:
- 3.5.0
- Disclosed:
- May 28, 2026
CVE-2026-27407 on NVD →
AI Engine 3.4.9 - Authenticated (Subscriber+) Privilege Escalation via Missing Authorization in MCP OAuth Bearer Token
high
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path, where any valid OAuth token causes MCP access to be granted without verifyi...
- CVSS:
- 8.8
- Affected:
- 3.4.9 – 3.4.9
- Fixed in:
- 3.5.0
- Disclosed:
- May 16, 2026
CVE-2026-8719 on NVD →
AI Engine – The Chatbot, AI Framework & MCP for WordPress <= 3.3.2 - Authenticated (Editor+) Arbitrary File Upload
high
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 3.3.2. This makes it possible for authenticated attackers, with Editor-level access and above, to upload arbitrary files on...
- CVSS:
- 7.2
- Affected:
- up to 3.3.2
- Fixed in:
- 3.3.3
- Disclosed:
- Feb 25, 2026
CVE-2026-23802 on NVD →
AI Engine <= 3.3.2 - Authenticated (Editor+) Arbitrary File Upload via 'filename' Parameter in update_media_metadata Endpoint
high
The AI Engine – The Chatbot and AI Framework for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `rest_helpers_update_media_metadata` function in all versions up to, and including, 3.3.2. This makes it possible for authenticated attackers, with Editor-le...
- CVSS:
- 7.2
- Affected:
- up to 3.3.2
- Fixed in:
- 3.3.3
- Disclosed:
- Jan 27, 2026
CVE-2026-1400 on NVD →
AI Engine <= 3.3.2 - Authenticated (Subscriber+) Server-Side Request Forgery
medium
The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the 'get_audio' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web appli...
- CVSS:
- 6.4
- Affected:
- up to 3.3.2
- Fixed in:
- 3.3.3
- Disclosed:
- Jan 27, 2026
CVE-2026-0746 on NVD →
AI Engine <= 3.1.8 - Authenticated (Editor+) Server-Side Request Forgery
medium
The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.8 via the rest_helpers_create_images function. This makes it possible for authenticated attackers, with Editor-level access and above, to make web requests to arbitrary locations originating from th...
- CVSS:
- 6.8
- Affected:
- up to 3.1.8
- Fixed in:
- 3.1.9
- Disclosed:
- Nov 18, 2025
CVE-2025-8084 on NVD →
AI Engine [ai-engine] < 3.1.9
unknown
[en] The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to, and including, 3.1.8 via deserialization of untrusted input in the 'rest_simpleTranscribeAudio' and 'rest_simpleVisionQuery' functions. This makes it possible for authenticated attackers, with S...
- Affected:
- up to 3.1.9
- Fixed in:
- 3.1.9
- Disclosed:
- Nov 13, 2025
CVE-2025-12844 on NVD →
AI Engine <= 3.1.8 - Authenticated (Subscriber+) PHP Object Injection via PHAR Deserialization
high
The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to, and including, 3.1.8 via deserialization of untrusted input in the 'rest_simpleTranscribeAudio' and 'rest_simpleVisionQuery' functions. This makes it possible for authenticated attackers, with Subscr...
- CVSS:
- 7.1
- Affected:
- up to 3.1.8
- Fixed in:
- 3.1.9
- Disclosed:
- Nov 12, 2025
CVE-2025-12844 on NVD →
AI Engine [ai-engine] < 3.1.4
unknown
[en] The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the /mcp/v1/ REST API endpoint that exposes the 'Bearer Token' value when 'No-Auth URL' is enabled. This makes it possible for unauthenticated attackers to extract the bearer token, wh...
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Nov 5, 2025
CVE-2025-11749 on NVD →
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
critical
The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the /mcp/v1/ REST API endpoint that exposes the 'Bearer Token' value when 'No-Auth URL' is enabled. This makes it possible for unauthenticated attackers to extract the bearer token, which c...
- CVSS:
- 9.8
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.4
- Disclosed:
- Nov 4, 2025
CVE-2025-11749 on NVD →
Ai Engine <= 2.9.5 - Missing Authorization to Unauthenticated Uploaded Files Disclosure And Deletion
medium
The AI Engine plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the rest_list and delete_files functions in all versions up to, and including, 2.9.5. This makes it possible for unauthenticated attackers to list and delete files uploaded by other users.
- CVSS:
- 6.5
- Affected:
- up to 2.9.5
- Fixed in:
- 2.9.6
- Disclosed:
- Sep 3, 2025
CVE-2025-8268 on NVD →
AI Engine 2.9.3 - 2.9.4 - Authenticated (Subscriber+) Arbitrary File Upload
high
The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_simpleFileUpload() function in versions 2.9.3 and 2.9.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's...
- CVSS:
- 8.8
- Affected:
- 2.9.3 – 2.9.4
- Fixed in:
- 2.9.5
- Disclosed:
- Jul 30, 2025
CVE-2025-7847 on NVD →
AI Engine <= 2.9.4 - Missing URL Scheme Validation to Authenticated (Subscriber+) Arbitrary File Read via simpleTranscribeAudio and get_audio Functions
medium
The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4. The simpleTranscribeAudio endpoint fails to restrict URL schemes before calling get_audio(). This makes it possible for authenticated attackers, with Subscriber-level access and above, to read...
- CVSS:
- 6.5
- Affected:
- up to 2.9.4
- Fixed in:
- 2.9.5
- Disclosed:
- Jul 23, 2025
CVE-2025-7780 on NVD →
AI Engine <= 2.8.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via `mwai_chatbot` Shortcode `id` Parameter
medium
The AI Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the mwai_chatbot shortcode 'id' parameter in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above...
- CVSS:
- 5.4
- Affected:
- up to 2.8.4
- Fixed in:
- 2.8.5
- Disclosed:
- Jul 7, 2025
CVE-2025-5570 on NVD →
AI Engine 2.8.4 - Insecure OAuth Implementation
high
The AI Engine plugin for WordPress is vulnerable to open redirect in version 2.8.4. This is due to an insecure OAuth implementation, as the 'redirect_uri' parameter is missing validation during the authorization flow. This makes it possible for unauthenticated attackers to intercept the authorization code and obtain an...
- CVSS:
- 8
- Affected:
- 2.8.4 – 2.8.4
- Fixed in:
- 2.8.5
- Disclosed:
- Jul 3, 2025
CVE-2025-6238 on NVD →
AI Engine 2.8.0 - 2.8.3 - Authenticated (Subscriber+) Insufficient Authorization to Privilege Escalation via MCP
high
The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'Meow_MWAI_Labs_MCP::can_access_mcp' function in versions 2.8.0 to 2.8.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to have fu...
- CVSS:
- 8.8
- Affected:
- 2.8.0 – 2.8.3
- Fixed in:
- 2.8.4
- Disclosed:
- Jun 18, 2025
CVE-2025-5071 on NVD →
AI Engine [ai-engine] < 2.6.5
unknown
[en] The AI Engine WordPress plugin before 2.6.5 does not sanitize and escape a parameter from one of its RESP API endpoint before using it in a SQL statement, allowing admins to perform SQL injection attacks
- Affected:
- up to 2.6.5
- Fixed in:
- 2.6.5
- Disclosed:
- Dec 12, 2024
CVE-2024-10499 on NVD →
AI Engine <= 2.6.3 - Authenticated (Admin+) SQL Injection
medium
The AI Engine plugin for WordPress is vulnerable to SQL Injection via the 'value' parameter in all versions up to, and including, 2.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Admi...
- CVSS:
- 4.9
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.5
- Disclosed:
- Nov 21, 2024
CVE-2024-10499 on NVD →
AI Engine [ai-engine] < 2.4.8
unknown
[en] The AI Engine WordPress plugin before 2.4.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when viewing chatbot discussions.
- Affected:
- up to 2.4.8
- Fixed in:
- 2.4.8
- Disclosed:
- Sep 13, 2024
CVE-2024-6723 on NVD →
AI Engine <= 2.4.7 - Authenticated (Admin+) SQL Injection
medium
The AI Engine plugin for WordPress is vulnerable to SQL Injection via the sort[accessor] parameter in all versions up to, and including, 2.4.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, wi...
- CVSS:
- 4.9
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.8
- Disclosed:
- Aug 22, 2024
CVE-2024-6723 on NVD →
AI Engine [ai-engine] < 2.5.1
unknown
[en] AI Engine < 2.4.3 is susceptible to remote-code-execution (RCE) via Log Poisoning. The AI Engine WordPress plugin before 2.5.1 fails to validate the file extension of "logs_path", allowing Administrators to change log filetypes from .log to .php.
- Affected:
- up to 2.5.1
- Fixed in:
- 2.5.1
- Disclosed:
- Aug 19, 2024
CVE-2024-6451 on NVD →
AI Engine [ai-engine] < 2.4.8
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot allows Server Side Request Forgery.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.4.7.
- Affected:
- up to 2.4.8
- Fixed in:
- 2.4.8
- Disclosed:
- Aug 1, 2024
CVE-2024-38791 on NVD →
AI Engine <= 2.5.0 - Authenticated (Admin+) Remote Code Execution
high
The AI Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.5.0 via the /wp-json/mwai/v1/settings/update REST API endpoint. This is due to the plugin not properly validating a log path file extension allowing a user to set the log extension as .php making the file e...
- CVSS:
- 7.2
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.1
- Disclosed:
- Jul 29, 2024
CVE-2024-6451 on NVD →
AI Engine <= 2.4.7 - Authenticated (Subscriber+) Server-Side Request Forgery
medium
The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.4.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to q...
- CVSS:
- 6.4
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.8
- Disclosed:
- Jul 22, 2024
CVE-2024-38791 on NVD →
AI Engine [ai-engine] < 2.2.70
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.2.63.
- Affected:
- up to 2.2.70
- Fixed in:
- 2.2.70
- Disclosed:
- May 13, 2024
CVE-2024-34440 on NVD →
AI Engine: ChatGPT Chatbot <= 2.2.63 - Authenticated (Editor+) Arbitrary File Upload
critical
The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 2.2.63. This makes it possible for authenticated attackers, with Editor-level access and above, to upload arbitrary files on the affected site's server which may make remo...
- CVSS:
- 9.1
- Affected:
- up to 2.2.63
- Fixed in:
- 2.2.70
- Disclosed:
- May 7, 2024
CVE-2024-34440 on NVD →
AI Engine [ai-engine] < 1.9.99
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 1.9.98.
- Affected:
- up to 1.9.99
- Fixed in:
- 1.9.99
- Disclosed:
- Apr 12, 2024
CVE-2023-51409 on NVD →
AI Engine [ai-engine] < 2.1.5
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.
- Affected:
- up to 2.1.5
- Fixed in:
- 2.1.5
- Disclosed:
- Mar 28, 2024
CVE-2024-29100 on NVD →
AI Engine [ai-engine] < 2.1.5
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.
- Affected:
- up to 2.1.5
- Fixed in:
- 2.1.5
- Disclosed:
- Mar 28, 2024
CVE-2024-29090 on NVD →
AI Engine <= 2.1.4 - Authenticated (Editor+) Server-Side Request Forgery
medium
The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.1.4 via the download_image function. This makes it possible for authenticated attackers, with editor-level access and above, to make web requests to arbitrary locations originating from the web applic...
- CVSS:
- 6.4
- Affected:
- up to 2.1.4
- Fixed in:
- 2.1.5
- Disclosed:
- Mar 26, 2024
CVE-2024-29090 on NVD →
AI Engine [ai-engine] < 2.2.1
unknown
[en] The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI chat data when discussion tracking is enabled in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible...
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.1
- Disclosed:
- Mar 2, 2024
CVE-2024-0378 on NVD →
AI Engine <= 2.2.0 - Unauthenticated Stored Cross-Site Scripting
medium
The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI chat data when discussion tracking is enabled in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for u...
- CVSS:
- 6.5
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.1
- Disclosed:
- Mar 1, 2024
CVE-2024-0378 on NVD →
AI Engine [ai-engine] < 2.1.5
unknown
[en] The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'add_image_from_url' function in all versions up to, and including, 2.1.4. This makes it possible for authenticated attackers, with Editor access...
- Affected:
- up to 2.1.5
- Fixed in:
- 2.1.5
- Disclosed:
- Feb 5, 2024
CVE-2024-0699 on NVD →
AI Engine <= 2.1.4 - Authenticated(Editor+) Arbitrary File Upload via add_image_from_url
medium
The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'add_image_from_url' function in all versions up to, and including, 2.1.4. This makes it possible for authenticated attackers, with Editor access and a...
- CVSS:
- 6.6
- Affected:
- up to 2.1.4
- Fixed in:
- 2.1.5
- Disclosed:
- Jan 18, 2024
CVE-2024-0699 on NVD →
AI Engine [ai-engine] < 2.1.5
unknown
The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'add_image_from_url' function in all versions up to, and including, 2.1.4. This makes it possible for authenticated attackers, with Editor access and a...
- Affected:
- up to 2.1.5
- Fixed in:
- 2.1.5
- Disclosed:
- Jan 18, 2024
AI Engine: ChatGPT Chatbot <= 1.9.98 - Unauthenticated Arbitrary File Upload via rest_upload
critical
The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'rest_upload' function in all versions up to, and including, 1.9.98. This makes it possible for unauthenticated attackers to upload arbitrary files on...
- CVSS:
- 9.8
- Affected:
- up to 1.9.98
- Fixed in:
- 1.9.99
- Disclosed:
- Jan 9, 2024
CVE-2023-51409 on NVD →
AI Engine [ai-engine] < 4.7.8
unknown
[en] The AI ChatBot WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 4.7.8
- Fixed in:
- 4.7.8
- Disclosed:
- Sep 4, 2023
CVE-2023-4253 on NVD →
AI Engine [ai-engine] < 1.6.83
unknown
[en] The AI Engine WordPress plugin before 1.6.83 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).
- Affected:
- up to 1.6.83
- Fixed in:
- 1.6.83
- Disclosed:
- Jun 27, 2023
CVE-2023-2580 on NVD →
AI Engine: ChatGPT Chatbot, Content Generator, GPT 3 & 4, Ultra-Customizable <= 1.6.82 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The AI Engine: ChatGPT Chatbot, Content Generator, GPT 3 & 4, Ultra-Customizable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in versions up to, and including, 1.6.82 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...
- CVSS:
- 4.4
- Affected:
- up to 1.6.83
- Fixed in:
- 1.6.83
- Disclosed:
- May 19, 2023
CVE-2023-2580 on NVD →
AI Engine [ai-engine] < 1.6.83
unknown
Update the WordPress AI Engine: ChatGPT Chatbot plugin to the latest available version (at least 1.6.83).
WPScanTeam discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress AI Engine: ChatGPT Chatbot Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, ad...
- Affected:
- up to 1.6.83
- Fixed in:
- 1.6.83
- Disclosed:
- May 19, 2023
AI Engine [ai-engine] < 1.6.83
unknown
The AI Engine: ChatGPT Chatbot, Content Generator, GPT 3 & 4, Ultra-Customizable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in versions up to, and including, 1.6.82 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...
- Affected:
- up to 1.6.83
- Fixed in:
- 1.6.83
- Disclosed:
- May 19, 2023
AI Engine [ai-engine] >= 2.9.3 - < 2.9.5
unknown
- Affected:
- 2.9.3 – 2.9.5
- Fixed in:
- 2.9.5
CVE-2025-7847 on NVD →
AI Engine [ai-engine] < 2.9.5
unknown
- Affected:
- up to 2.9.5
- Fixed in:
- 2.9.5
CVE-2025-7780 on NVD →
AI Engine [ai-engine] < 2.8.5
unknown
- Affected:
- up to 2.8.5
- Fixed in:
- 2.8.5
CVE-2025-5570 on NVD →
AI Engine [ai-engine] < 2.8.5
unknown
- Affected:
- up to 2.8.5
- Fixed in:
- 2.8.5
CVE-2025-6238 on NVD →
AI Engine [ai-engine] >= 2.8.0 - < 2.8.4
unknown
- Affected:
- 2.8.0 – 2.8.4
- Fixed in:
- 2.8.4
CVE-2025-5071 on NVD →