VYPR

AI Engine

by WordPress

Source repositories

CVEs (33)

  • CVE-2025-12844HigNov 13, 2025
    risk 0.39cvss 7.1epss 0.00

    The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to, and including, 3.1.8 via deserialization of untrusted input in the 'rest_simpleTranscribeAudio' and 'rest_simpleVisionQuery' functions. This makes it possible…

  • CVE-2026-89141MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via the 'mediaId' parameter due to missing validation on a user controlled key. This makes it…

  • CVE-2026-0746MedJan 27, 2026
    risk 0.35cvss 6.4epss 0.00

    The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the 'get_audio' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary…

  • CVE-2025-7780MedJul 24, 2025
    risk 0.35cvss 6.5epss 0.01

    The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4. The simpleTranscribeAudio endpoint fails to restrict URL schemes before calling get_audio(). This makes it possible for authenticated attackers, with…

  • CVE-2025-5570MedJul 8, 2025
    risk 0.35cvss 5.4epss 0.00

    The AI Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the mwai_chatbot shortcode 'id' parameter in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2026-75798MedAug 26, 2026
    risk 0.34cvss 5.3epss 0.00

    The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only features, relying instead on a token it hands out to anonymous visitors, allowing unauthenticated attackers to run AI queries of their own choosing against the…

  • CVE-2026-16955MedAug 8, 2026
    risk 0.33cvss 5.0epss 0.00

    The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host.…

  • CVE-2024-38791MedAug 1, 2024
    risk 0.32cvss 4.9epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot allows Server Side Request Forgery.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.4.7.

  • CVE-2026-16953MedAug 8, 2026
    risk 0.31cvss 4.8epss 0.00

    The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deletion, authorising the action solely by a client-supplied session cookie value, so an unauthenticated attacker who obtains a victim's session identifier and file…

  • CVE-2024-6723MedSep 13, 2024
    risk 0.31cvss 4.7epss 0.00

    The AI Engine WordPress plugin before 2.4.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when viewing chatbot discussions.

  • CVE-2023-2580MedJun 27, 2023
    risk 0.31cvss 4.8epss 0.00

    The AI Engine WordPress plugin before 1.6.83 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite…

  • CVE-2026-12510MedJul 16, 2026
    risk 0.00cvss 5.9epss 0.00

    The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, allowing users with subscriber-level access to read other users' private conversations and take over their conversation records when…

  • CVE-2026-12511HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.00

    The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authenticated users with editor-level access to write attacker-controlled bytes to an arbitrary location on the server via path traversal.

Page 2 of 2