The AI Engine plugin for WordPress has a security issue called Server-Side Request Forgery. This means that anyone who is logged in with at least subscriber-level access can make requests to other websites without permission. This can be used to access and change information from internal services.