AI Engine
cpe:2.3:a:ai_engine_project:ai_engine:*:*:*:*:wordpress:*:*
- < 3.5.5
A vulnerability in the AI Engine WordPress plugin, affecting versions prior to 3.5.5, allows users with subscriber-level access to read private conversations of other users and take over their conversation records. This issue arises because the plugin does not verify ownership of chatbot conversations referenced by user-supplied identifiers. The vulnerability is exploitable when the discussions feature is enabled.
Exploitation of this vulnerability allows for unauthorized access to private chatbot conversations of other users, as well as the ability to take over and manage those conversations.
To reproduce this vulnerability, first enable the Discussions feature in the AI Engine plugin settings. After configuring a chatbot with an AI provider, create two user accounts: one for the victim and one for the attacker (who must have subscriber-level access). The attacker needs to know the victim's chat ID, which can be easily obtained if the site uses a fixed custom ID or shortcode ID, or through referrer/browser history leakage. 1. Have the victim create a private discussion. 2. The attacker can then submit a chat referencing the victim's chat ID. Once the bot replies, the ownership of the discussion is transferred to the attacker. 3. Finally, the attacker can list their own discussions, which will now include the victim's discussion and its full history.
Users are advised to update the AI Engine WordPress plugin to version 3.5.5 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.