PLUGIN SECURITY

Is Ai Engine safe?

AI meets WordPress. Your site can now chat, write poetry, solve problems, and maybe make you coffee.

What this plugin does

  • Slug: ai-engine
  • Author: Jordy Meow
  • 100000+ active installs
  • 98/100 rating (860 reviews on wordpress.org)
  • 7460125 all-time downloads
  • On WordPress.org since 2022-12-27

AIchatbotClaudegptopenai

Maintenance status

  • Latest known version: 3.7.0
  • Last updated: 2026-08-20 5:19pm GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 8.1+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

36 known CVEs on file for Ai Engine.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-75798 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.7.2 Missing Authorization Unknown < 3.7.2 3.7.2 2026-08-26 ⚠ update needed
CVE-2026-75797 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.7.2 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Unknown < 3.7.2 3.7.2 2026-08-26 ⚠ update needed
CVE-2026-75796 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.6.1 Improper Privilege Management Unknown < 3.6.1 3.6.1 2026-08-21 ✓ fixed in latest
CVE-2026-16955 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.6.6 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Unknown < 3.6.6 3.6.6 2026-08-08 ✓ fixed in latest
CVE-2026-16953 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.6.4 Authorization Bypass Through User-Controlled Key Unknown < 3.6.4 3.6.4 2026-08-08 ✓ fixed in latest
CVE-2026-16954 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.6.4 Exposure of Sensitive Information to an Unauthorized Actor Unknown < 3.6.4 3.6.4 2026-08-06 ✓ fixed in latest
CVE-2026-15988 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.6.6 Cross-Site Request Forgery (CSRF) High 8.8 < 3.6.6 3.6.6 2026-07-31 ✓ fixed in latest
CVE-2026-65545 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.6.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.6.9 3.6.9 2026-07-28 ✓ fixed in latest
+ 40 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12510 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.5.5 Authorization Bypass Through User-Controlled Key Unknown < 3.5.5 3.5.5 2026-06-25 ✓ fixed in latest
CVE-2026-12511 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.5.5 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Unknown < 3.5.5 3.5.5 2026-06-23 ✓ fixed in latest
CVE-2026-27407 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.5.0 Incorrect Privilege Assignment High 7.2 < 3.5.0 3.5.0 2026-05-28 ✓ fixed in latest
CVE-2026-8719 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.5.0 Improper Privilege Management High 8.8 < 3.5.0 3.5.0 2026-05-16 ✓ fixed in latest
CVE-2026-23802 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.3.3 Unrestricted Upload of File with Dangerous Type Critical 9.1 < 3.3.3 3.3.3 2026-02-25 ✓ fixed in latest
CVE-2025-12844 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.1.9 Deserialization of Untrusted Data High 7.1 < 3.1.9 3.1.9 2025-11-12 ✓ fixed in latest
CVE-2025-11749 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.1.4 Exposure of Sensitive Information to an Unauthorized Actor Critical 9.8 < 3.1.4 3.1.4 2025-11-04 ✓ fixed in latest
CVE-2024-10499 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 2.6.5 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.2 < 2.6.5 2.6.5 2024-11-21 ✓ fixed in latest
CVE-2024-6723 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 2.4.8 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 4.7 < 2.4.8 2.4.8 2024-08-22 ✓ fixed in latest
CVE-2024-6451 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 2.5.1 Improper Control of Generation of Code ('Code Injection') High 7.2 < 2.5.1 2.5.1 2024-07-29 ✓ fixed in latest
CVE-2024-38791 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 2.4.8 Server-Side Request Forgery (SSRF) High 7.1 < 2.4.8 2.4.8 2024-07-22 ✓ fixed in latest
CVE-2024-34440 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 2.2.70 Unrestricted Upload of File with Dangerous Type High 7.2 < 2.2.70 2.2.70 2024-05-07 ✓ fixed in latest
CVE-2024-29100 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 2.1.5 Unrestricted Upload of File with Dangerous Type Critical 9.1 < 2.1.5 2.1.5 2024-03-28 ✓ fixed in latest
CVE-2024-29090 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 2.1.5 Server-Side Request Forgery (SSRF) Medium 6.8 < 2.1.5 2.1.5 2024-03-26 ✓ fixed in latest
CVE-2024-0378 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 2.2.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.2.1 2.2.1 2024-03-01 ✓ fixed in latest
CVE-2024-0699 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 2.1.5 Unrestricted Upload of File with Dangerous Type High 7.2 < 2.1.5 2.1.5 2024-01-18 ✓ fixed in latest
CVE-2023-51409 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 1.9.99 Unrestricted Upload of File with Dangerous Type Critical 10.0 < 1.9.99 1.9.99 2024-01-09 ✓ fixed in latest
CVE-2023-4253 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 4.7.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 4.7.8 4.7.8 2023-08-10 ⚠ update needed
CVE-2023-2580 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 1.6.83 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 1.6.83 1.6.83 2023-05-19 ✓ fixed in latest
AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 1.6.83 Unknown < 1.6.83 1.6.83 2023-05-19 ✓ fixed in latest
AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] >= 2.8.0 - < 2.8.4 Incorrect Authorization High 8.8 2.8.0–2.8.4 2.8.4 0000-00-00 ✓ fixed in latest
AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 2.8.5 URL Redirection to Untrusted Site ('Open Redirect') High 8.0 < 2.8.5 2.8.5 0000-00-00 ✓ fixed in latest
AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 2.8.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.8.5 2.8.5 0000-00-00 ✓ fixed in latest
AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 2.9.5 Exposure of Sensitive Information to an Unauthorized Actor Medium 6.5 < 2.9.5 2.9.5 0000-00-00 ✓ fixed in latest
AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] >= 2.9.3 - < 2.9.5 Unrestricted Upload of File with Dangerous Type High 8.8 2.9.3–2.9.5 2.9.5 0000-00-00 ✓ fixed in latest
AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.3.3 Unknown < 3.3.3 3.3.3 0000-00-00 ✓ fixed in latest
AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.3.3 Unknown < 3.3.3 3.3.3 0000-00-00 ✓ fixed in latest
AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 2.9.6 Medium 6.5 < 2.9.6 2.9.6 0000-00-00 ✓ fixed in latest
AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.1.9 Unknown < 3.1.9 3.1.9 0000-00-00 ✓ fixed in latest
CVE-2023-2580 AI-Engine < 1.6.83 - Admin+ Stored XSS Unknown < 1.6.83 1.6.83 ✓ fixed in latest
CVE-2024-0699 AI Engine < 2.1.5 - Editor+ Arbitrary File Upload via add_image_from_url Unknown < 2.1.5 2.1.5 ✓ fixed in latest
CVE-2025-5071 AI Engine 2.8.0 - 2.8.3 - Subscriber+ Privilege Escalation via MCP Unknown < 2.8.4 2.8.4 ✓ fixed in latest
CVE-2025-6238 AI Engine 2.8.4 - Insecure OAuth Implementation Unknown < 2.8.5 2.8.5 ✓ fixed in latest
CVE-2025-5570 AI Engine < 2.8.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via `mwai_chatbot` Shortcode `id` Parameter Unknown < 2.8.5 2.8.5 ✓ fixed in latest
CVE-2025-7780 AI Engine < 2.9.5 - Missing URL Scheme Validation to Authenticated (Subscriber+) Arbitrary File Read via simpleTranscribeAudio and get_audio Functions Unknown < 2.9.5 2.9.5 ✓ fixed in latest
CVE-2025-7847 AI Engine 2.9.3 - 2.9.4 - Subscriber+ Arbitrary File Upload Unknown < 2.9.5 2.9.5 ✓ fixed in latest
CVE-2025-8268 Ai Engine < 2.9.6 - Missing Authorization to Unauthenticated Uploaded Files Disclosure And Deletion Unknown < 2.9.6 2.9.6 ✓ fixed in latest
CVE-2025-8084 AI Engine < 3.1.9 - Authenticated (Editor+) Server-Side Request Forgery Unknown < 3.1.9 3.1.9 ✓ fixed in latest
CVE-2026-0746 AI Engine < 3.3.3 - Authenticated (Subscriber+) Server-Side Request Forgery Unknown < 3.3.3 3.3.3 ✓ fixed in latest
CVE-2026-1400 AI Engine < 3.3.3 - Editor+ Arbitrary File Upload Unknown < 3.3.3 3.3.3 ✓ fixed in latest

How to fix it

Keep Ai Engine updated — 3.7.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.