AI Engine – The Chatbot, AI Framework & MCP for WordPress

Information

Software Type Plugin
Software Slug ai-engine (view on wordpress.org)
Software Status Active
Software Author tigroumeow
Software Website wordpress.org
Software Downloads 7,379,006
Software Active Installs 100,000
Software Record Last Updated August 14, 2026

Showing 1-20 of 28 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation Patched CVE-2025-11749 9.8 Emiliano Versini November 4, 2025
AI Engine: ChatGPT Chatbot <= 1.9.98 - Unauthenticated Arbitrary File Upload via rest_upload Patched CVE-2023-51409 9.8 Rafie Muhammad January 9, 2024
AI Engine: ChatGPT Chatbot <= 2.2.63 - Authenticated (Editor+) Arbitrary File Upload Patched CVE-2024-34440 9.1 stealthcopter May 7, 2024
AI Engine <= 3.6.5 - Cross-Site Request Forgery to Privilege Escalation via REQUEST_URI Substring Match Patched CVE-2026-15988 8.8 UKO July 31, 2026
AI Engine 3.4.9 - Authenticated (Subscriber+) Privilege Escalation via Missing Authorization in MCP OAuth Bearer Token Patched CVE-2026-8719 8.8 daroo May 16, 2026
AI Engine 2.9.3 - 2.9.4 - Authenticated (Subscriber+) Arbitrary File Upload Patched CVE-2025-7847 8.8 ISMAILSHADOW July 30, 2025
AI Engine 2.8.0 - 2.8.3 - Authenticated (Subscriber+) Insufficient Authorization to Privilege Escalation via MCP Patched CVE-2025-5071 8.8 István Márton June 18, 2025
AI Engine 2.8.4 - Insecure OAuth Implementation Patched CVE-2025-6238 8.0 István Márton July 3, 2025
AI Engine – The Chatbot, AI Framework & MCP for WordPress <= 3.6.8 - Unauthenticated Stored Cross-Site Scripting Patched CVE-2026-65545 7.2 daroo July 28, 2026
AI Engine <= 3.5.4 - Authenticated (Editor+) Arbitrary File Write Patched CVE-2026-12511 7.2 Meher Sudhakar Abbireddi June 23, 2026
AI Engine – The Chatbot, AI Framework & MCP for WordPress <= 3.4.9 - Authenticated (Editor+) Privilege Escalation Patched CVE-2026-27407 7.2 Phat RiO May 28, 2026
AI Engine – The Chatbot, AI Framework & MCP for WordPress <= 3.3.2 - Authenticated (Editor+) Arbitrary File Upload Patched CVE-2026-23802 7.2 0xd4rk5id3 February 25, 2026
AI Engine <= 3.3.2 - Authenticated (Editor+) Arbitrary File Upload via 'filename' Parameter in update_media_metadata Endpoint Patched CVE-2026-1400 7.2 type5afe January 27, 2026
AI Engine <= 2.5.0 - Authenticated (Admin+) Remote Code Execution Patched CVE-2024-6451 7.2 Karolis Narvilas July 29, 2024
AI Engine <= 3.1.8 - Authenticated (Subscriber+) PHP Object Injection via PHAR Deserialization Patched CVE-2025-12844 7.1 ISMAILSHADOW November 12, 2025
AI Engine <= 3.1.8 - Authenticated (Editor+) Server-Side Request Forgery Patched CVE-2025-8084 6.8 Jonas Benjamin Friedli November 18, 2025
AI Engine <= 2.1.4 - Authenticated(Editor+) Arbitrary File Upload via add_image_from_url Patched CVE-2024-0699 6.6 rootxsudip January 18, 2024
Ai Engine <= 2.9.5 - Missing Authorization to Unauthenticated Uploaded Files Disclosure And Deletion Patched CVE-2025-8268 6.5 ISMAILSHADOW September 3, 2025
AI Engine <= 2.9.4 - Missing URL Scheme Validation to Authenticated (Subscriber+) Arbitrary File Read via simpleTranscribeAudio and get_audio Functions Patched CVE-2025-7780 6.5 ISMAILSHADOW July 23, 2025
AI Engine <= 2.2.0 - Unauthenticated Stored Cross-Site Scripting Patched CVE-2024-0378 6.5 rootxsudip March 1, 2024

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation