The AI Engine plugin for WordPress, which includes features like chatbots, generators, assistants, and GPT 4, has a security vulnerability that allows for unauthorized file uploads. This means that someone with the right access (Editor or higher) could upload any type of file to the website’s server, potentially allowing them to run code remotely.