WordPress Plugin Vulnerabilities

AI Engine < 3.6.4 - Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie

Description

The plugin does not verify ownership of a guest's uploaded chatbot files before deletion, authorising the action solely by a client-supplied session cookie value, so an unauthenticated attacker who obtains a victim's session identifier and file reference can delete that victim's uploaded files.

Proof of Concept

Affects Plugins

Fixed in 3.6.4

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Revanth Hari Narayana Matte
Submitter
Revanth Hari Narayana Matte
Verified
Yes

Timeline

Publicly Published
2026-08-03 (about 26 days ago)
Added
2026-08-03 (about 25 days ago)
Last Updated
2026-08-03 (about 25 days ago)

Other