Input validation vulnerability in AI Engine 3.1.8

The AI Engine plugin used in WordPress has a security issue that allows for a type of attack called Server-Side Request Forgery. This can happen in any version up to version 3.1.8 through a function called rest_helpers_create_images. This means that someone who is logged in and has Editor-level permissions or higher can make requests to other websites through the plugin. This could potentially give them access to private information from internal services. On Cloud instances, this vulnerability can also be used to retrieve metadata.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.