The AI Engine plugin for WordPress has a security issue in version 2.8.4. This is because the way it handles OAuth does not properly check for a valid redirect URL. This means that someone without proper authorization can direct a user to a fake website and obtain sensitive information. This vulnerability has been fixed in version 2.8.5 by disabling OAuth.