AI Engine <= 3.1.8 - Authenticated (Editor+) Server-Side Request Forgery
AI Engine – The Chatbot, AI Framework & MCP for WordPress
Minimum safe version
4.7.8
Update to 4.7.8 or later to address 27 fixable vulnerabilities
Ai Engine <= 2.9.5 - Missing Authorization to Unauthenticated Uploaded Files Disclosure And Deletion
AI Engine <= 3.3.2 - Authenticated (Subscriber+) Server-Side Request Forgery
AI Engine <= 3.3.2 - Authenticated (Editor+) Arbitrary File Upload via 'filename' Parameter in update_media_metadata Endpoint
CVE-2026-23802
CVE-2025-12844
CVE-2025-11749
AI Engine 2.9.3 - 2.9.4 - Authenticated (Subscriber+) Arbitrary File Upload
AI Engine <= 2.9.4 - Missing URL Scheme Validation to Authenticated (Subscriber+) Arbitrary File Read via simpleTranscribeAudio and get_audio Functions
AI Engine <= 2.8.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via `mwai_chatbot` Shortcode `id` Parameter
AI Engine 2.8.4 - Insecure OAuth Implementation
AI Engine 2.8.0 - 2.8.3 - Authenticated (Subscriber+) Insufficient Authorization to Privilege Escalation via MCP
CVE-2024-10499
CVE-2024-6723
CVE-2024-6451
CVE-2024-38791
CVE-2024-34440
CVE-2024-29090
CVE-2024-29100
CVE-2024-0378
CVE-2024-0699
AI Engine <= 2.1.4 - Authenticated(Editor+) Arbitrary File Upload via add_image_from_url
CVE-2023-51409
CVE-2023-4253
CVE-2023-2580
WordPress AI Engine: ChatGPT Chatbot Plugin < 1.6.83 is vulnerable to Cross Site Scripting (XSS)
AI Engine: ChatGPT Chatbot, Content Generator, GPT 3 & 4, Ultra-Customizable <= 1.6.82 - Authenticated (Admin+) Stored Cross-Site Scripting