Extension WordPress

Vulnérabilités AI Engine – The Chatbot, AI Framework & MCP for WordPress

Cette page rassemble les failles publiées pour AI Engine – The Chatbot, AI Framework & MCP for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.

24Vulnérabilités
3Critiques
24Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de AI Engine – The Chatbot, AI Framework & MCP for WordPress

24 fiches

CVE-2026-27407 Élevée · 7,2
AI Engine – The Chatbot, AI Framework & MCP for WordPress

AI Engine – The Chatbot, AI Framework & MCP for WordPress <= 3.4.9 – Authenticated (Editor+) Privilege Escalation

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.4.9. This makes it possible for authenticated attackers, with Editor-level access…

Versions affectées

*-3.4.9

Correctif

3.5.0

Publication

28/05/2026

CVE-2026-8719 Élevée · 8,8
AI Engine – The Chatbot, AI Framework & MCP for WordPress

AI Engine 3.4.9 – Authenticated (Subscriber+) Privilege Escalation via Missing Authorization in MCP OAuth Bearer Token

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path,…

Versions affectées

3.4.9

Correctif

3.5.0

Publication

16/05/2026

CVE-2026-23802 Élevée · 7,2
AI Engine – The Chatbot, AI Framework & MCP for WordPress

AI Engine – The Chatbot, AI Framework & MCP for WordPress <= 3.3.2 – Authenticated (Editor+) Arbitrary File Upload

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 3.3.2. This makes it…

Versions affectées

*-3.3.2

Correctif

3.3.3

Publication

25/02/2026

CVE-2026-1400 Élevée · 7,2
AI Engine – The Chatbot, AI Framework & MCP for WordPress

AI Engine <= 3.3.2 – Authenticated (Editor+) Arbitrary File Upload via 'filename' Parameter in update_media_metadata Endpoint

The AI Engine – The Chatbot and AI Framework for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `rest_helpers_update_media_metadata` function in all versions up to, and including, 3.3.2.…

Versions affectées

*-3.3.2

Correctif

3.3.3

Publication

27/01/2026

CVE-2026-0746 Moyenne · 6,4
AI Engine – The Chatbot, AI Framework & MCP for WordPress

AI Engine <= 3.3.2 – Authenticated (Subscriber+) Server-Side Request Forgery

The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the 'get_audio' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make…

Versions affectées

*-3.3.2

Correctif

3.3.3

Publication

27/01/2026

CVE-2025-8084 Moyenne · 6,8
AI Engine – The Chatbot, AI Framework & MCP for WordPress

AI Engine <= 3.1.8 – Authenticated (Editor+) Server-Side Request Forgery

The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.8 via the rest_helpers_create_images function. This makes it possible for authenticated attackers, with Editor-level access and above, to make…

Versions affectées

*-3.1.8

Correctif

3.1.9

Publication

18/11/2025

CVE-2025-12844 Élevée · 7,1
AI Engine – The Chatbot, AI Framework & MCP for WordPress

AI Engine <= 3.1.8 – Authenticated (Subscriber+) PHP Object Injection via PHAR Deserialization

The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to, and including, 3.1.8 via deserialization of untrusted input in the 'rest_simpleTranscribeAudio' and 'rest_simpleVisionQuery' functions. This makes it possible…

Versions affectées

*-3.1.8

Correctif

3.1.9

Publication

12/11/2025

CVE-2025-11749 Critique · 9,8
AI Engine – The Chatbot, AI Framework & MCP for WordPress

AI Engine <= 3.1.3 – Unauthenticated Sensitive Information Exposure to Privilege Escalation

The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the /mcp/v1/ REST API endpoint that exposes the 'Bearer Token' value when 'No-Auth URL' is enabled. This…

Versions affectées

*-3.1.3

Correctif

3.1.4

Publication

04/11/2025

CVE-2025-8268 Moyenne · 6,5
AI Engine – The Chatbot, AI Framework & MCP for WordPress

Ai Engine <= 2.9.5 – Missing Authorization to Unauthenticated Uploaded Files Disclosure And Deletion

The AI Engine plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the rest_list and delete_files functions in all versions up to, and including, 2.9.5. This makes it…

Versions affectées

*-2.9.5

Correctif

2.9.6

Publication

03/09/2025

CVE-2025-7847 Élevée · 8,8
AI Engine – The Chatbot, AI Framework & MCP for WordPress

AI Engine 2.9.3 – 2.9.4 – Authenticated (Subscriber+) Arbitrary File Upload

The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_simpleFileUpload() function in versions 2.9.3 and 2.9.4. This makes it possible for authenticated attackers, with Subscriber-level access and…

Versions affectées

2.9.3-2.9.4

Correctif

2.9.5

Publication

30/07/2025

CVE-2025-7780 Moyenne · 6,5
AI Engine – The Chatbot, AI Framework & MCP for WordPress

AI Engine <= 2.9.4 – Missing URL Scheme Validation to Authenticated (Subscriber+) Arbitrary File Read via simpleTranscribeAudio and get_audio Functions

The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4. The simpleTranscribeAudio endpoint fails to restrict URL schemes before calling get_audio(). This makes it possible for authenticated attackers,…

Versions affectées

*-2.9.4

Correctif

2.9.5

Publication

23/07/2025

CVE-2025-5570 Moyenne · 5,4
AI Engine – The Chatbot, AI Framework & MCP for WordPress

AI Engine <= 2.8.4 – Authenticated (Subscriber+) Stored Cross-Site Scripting via `mwai_chatbot` Shortcode `id` Parameter

The AI Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the mwai_chatbot shortcode 'id' parameter in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-2.8.4

Correctif

2.8.5

Publication

07/07/2025

CVE-2025-5071 Élevée · 8,8
AI Engine – The Chatbot, AI Framework & MCP for WordPress

AI Engine 2.8.0 – 2.8.3 – Authenticated (Subscriber+) Insufficient Authorization to Privilege Escalation via MCP

The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'Meow_MWAI_Labs_MCP::can_access_mcp' function in versions 2.8.0 to 2.8.3. This makes it possible for authenticated…

Versions affectées

2.8.0-2.8.3

Correctif

2.8.4

Publication

18/06/2025

CVE-2024-38791 Moyenne · 6,4
AI Engine – The Chatbot, AI Framework & MCP for WordPress

AI Engine <= 2.4.7 – Authenticated (Subscriber+) Server-Side Request Forgery

The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.4.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary…

Versions affectées

*-2.4.7

Correctif

2.4.8

Publication

22/07/2024

CVE-2024-34440 Critique · 9,1
AI Engine – The Chatbot, AI Framework & MCP for WordPress

AI Engine: ChatGPT Chatbot <= 2.2.63 – Authenticated (Editor+) Arbitrary File Upload

The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 2.2.63. This makes it possible for authenticated attackers, with Editor-level access and above,…

Versions affectées

*-2.2.63

Correctif

2.2.70

Publication

07/05/2024

CVE-2024-29090 Moyenne · 6,4
AI Engine – The Chatbot, AI Framework & MCP for WordPress

AI Engine <= 2.1.4 – Authenticated (Editor+) Server-Side Request Forgery

The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.1.4 via the download_image function. This makes it possible for authenticated attackers, with editor-level access and above, to make…

Versions affectées

*-2.1.4

Correctif

2.1.5

Publication

26/03/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités