WordPress Plugin Vulnerabilities

AI Engine < 3.5.5 - Subscriber+Chatbot Discussion Disclosure and Takeover via IDOR

Description

The plugin does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, allowing users with subscriber-level access to read other users' private conversations and take over their conversation records when the discussions feature is enabled.

Proof of Concept

Affects Plugins

Fixed in 3.5.5

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Shivamani Vastrala
Submitter
Shivamani Vastrala
Verified
Yes

Timeline

Publicly Published
2026-06-25 (about 2 months ago)
Added
2026-06-25 (about 2 months ago)
Last Updated
2026-06-25 (about 2 months ago)

Other