Vulnerabilities

Summary — last 7 days

New vulnerabilities3,333▲ 343 vs. last week
Critical / high1,493▲ 121 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 117 vs. last week
–

40 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ReceivedHigh (7.2)——Mowgli AI AI EngineAI10/1/202610/1/2026
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.0 This is due to a chain of missing input neutralization and output escaping across the /mwai-ui/v1/chats/submit REST endpoint, the PHP error-log parser…
DeferredMedium (5.3)0.23%—AI EngineAI9/23/20269/23/2026
Unauthenticated Insecure Direct Object References (IDOR) in AI Engine <= 3.7.8 versions.
DeferredMedium (6.5)0.45%—THE AI EngineAI9/15/20269/15/2026
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via the 'mediaId' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with…
DeferredMedium (5.3)0.30%—AI EngineAI8/26/20268/26/2026
The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only features, relying instead on a token it hands out to anonymous visitors, allowing unauthenticated attackers to run AI queries of their own choosing against the site owner's configured provider account.
DeferredHigh (7.7)0.44%—AI EngineAI8/26/20268/26/2026
The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local filesystem path before reading the file and forwarding its contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host.…
DeferredHigh (7.2)0.46%—AI EngineAI8/21/20268/26/2026
The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing privileged user management operations, allowing users with the Administrator role on a Multisite sub-site to take over any account on the network, including the Network…
DeferredMedium (5)0.34%—AI EngineAI8/8/20268/26/2026
The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level…
DeferredMedium (4.8)0.27%—AI EngineAI8/8/20268/26/2026
The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deletion, authorising the action solely by a client-supplied session cookie value, so an unauthenticated attacker who obtains a victim's session identifier and file reference can delete that victim's…
DeferredHigh (7.1)0.25%—AI EngineAI8/6/20268/12/2026
Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions.
DeferredMedium (6.5)0.43%—AI EngineAI8/6/20268/26/2026
The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admin page's inline script data, allowing users with the Editor role to read the site's stored third-party API key and authentication tokens in cleartext, despite those secrets being restricted to…
DeferredHigh (8.8)0.30%—AI EngineAI8/1/20268/12/2026
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_authorize function. This makes it possible for unauthenticated attackers to…
DeferredMedium (5.9)0.23%—AI EngineAI7/16/20267/16/2026
The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, allowing users with subscriber-level access to read other users' private conversations and take over their conversation records when the discussions feature is enabled.
DeferredHigh (8.1)0.47%—AI EngineAI7/14/20267/14/2026
The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authenticated users with editor-level access to write attacker-controlled bytes to an arbitrary location on the server via path traversal.
DeferredHigh (7.2)0.46%—AI EngineAI6/15/20266/17/2026
Editor Privilege Escalation in AI Engine <= 3.4.9 versions.
DeferredHigh (8.8)0.44%—AI EngineAI5/17/20266/17/2026
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path, where any valid OAuth token causes MCP access to be granted without…
DeferredMedium (4.3)0.23%—Jordymeow AI Engine PROAI4/8/20267/24/2026
Missing Authorization vulnerability in Jordy Meow AI Engine (Pro) ai-engine-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Engine (Pro): from n/a through < 3.4.2.
DeferredCritical (9.1)0.46%—Jordymeow AI EngineAI3/5/20266/17/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine ai-engine allows Using Malicious Files.This issue affects AI Engine: from n/a through <= 3.3.2.
DeferredHigh (7.2)0.74%—AI EngineAI1/28/20266/17/2026
The AI Engine – The Chatbot and AI Framework for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `rest_helpers_update_media_metadata` function in all versions up to, and including, 3.3.2. This makes it possible for authenticated attackers, with…
DeferredMedium (6.4)0.21%—AI EngineAI1/27/20266/17/2026
The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the 'get_audio' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web…
DeferredMedium (6.5)0.49%—LQD AI Engine FOR WordpressAI11/25/20256/17/2026
The AI Engine for WordPress: ChatGPT, GPT Content Generator plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.0.1. This is due to insufficient validation of user-supplied file paths in the 'lqdai_update_post' AJAX endpoint and the use of file_get_contents() with…
DeferredMedium (6.8)0.42%—AI EngineAI11/18/20256/17/2026
The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.8 via the rest_helpers_create_images function. This makes it possible for authenticated attackers, with Editor-level access and above, to make web requests to arbitrary locations originating from…
DeferredHigh (7.1)0.42%—AI EngineAI11/13/20256/17/2026
The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to, and including, 3.1.8 via deserialization of untrusted input in the 'rest_simpleTranscribeAudio' and 'rest_simpleVisionQuery' functions. This makes it possible for authenticated attackers, with…
DeferredCritical (9.8)75%—AI EngineAI11/5/20256/17/2026
The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the /mcp/v1/ REST API endpoint that exposes the 'Bearer Token' value when 'No-Auth URL' is enabled. This makes it possible for unauthenticated attackers to extract the bearer token, which…
DeferredMedium (6.5)0.27%—AI EngineAI9/3/20256/17/2026
The AI Engine plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the rest_list and delete_files functions in all versions up to, and including, 2.9.5. This makes it possible for unauthenticated attackers to list and delete files uploaded by other users.
DeferredHigh (8.8)1.1%—AI EngineAI7/31/20256/17/2026
The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_simpleFileUpload() function in versions 2.9.3 and 2.9.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected…