Input validation vulnerability in AI Engine – The Chatbot and AI Framework for WordPress 3.3.2

The AI Engine plugin for WordPress has a security issue that can be exploited by attackers who have Subscriber-level access or higher. This vulnerability allows them to make requests to any location from the web application, potentially accessing and changing information from internal services. This can happen if the “Public API” setting is enabled and ‘allow_url_fopen’ is set to ‘On’ on the server.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.