AI Engine WordPress Plugin Chatbot Conversation Takeover Vulnerability

Vulnerability

A vulnerability in the AI Engine WordPress plugin, affecting versions prior to 3.5.5, allows users with subscriber-level access to read private conversations of other users and take over their conversation records. This issue arises because the plugin does not verify ownership of chatbot conversations referenced by user-supplied identifiers. The vulnerability is exploitable when the discussions feature is enabled.

Impact

Exploitation of this vulnerability allows for unauthorized access to private chatbot conversations of other users, as well as the ability to take over and manage those conversations.

Reproduction

To reproduce this vulnerability, first enable the Discussions feature in the AI Engine plugin settings. After configuring a chatbot with an AI provider, create two user accounts: one for the victim and one for the attacker (who must have subscriber-level access). The attacker needs to know the victim's chat ID, which can be easily obtained if the site uses a fixed custom ID or shortcode ID, or through referrer/browser history leakage. 1. Have the victim create a private discussion. 2. The attacker can then submit a chat referencing the victim's chat ID. Once the bot replies, the ownership of the discussion is transferred to the attacker. 3. Finally, the attacker can list their own discussions, which will now include the victim's discussion and its full history.

Remediation

Users are advised to update the AI Engine WordPress plugin to version 3.5.5 or later.

Added: Jul 16, 2026, 7:27 AM
Updated: Jul 16, 2026, 7:27 AM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
1.3
exploitability
6.8
remediation
7.7
relevance
9.7
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.