Executive brief
AI Engine (Pro) is a WordPress plugin used to integrate artificial intelligence features into websites. A security flaw in the plugin's access control settings could allow logged-in users with low-level permissions to access features or data they should not be authorized to see. This could lead to unauthorized information disclosure or minor configuration changes depending on the specific site setup.
Technical details
A missing authorization (CWE-862) vulnerability exists in the Jordy Meow AI Engine (Pro) plugin for WordPress. The flaw is rooted in incorrectly configured access control security levels within the 'ai-engine-pro' component. An attacker with 'Contributor' level privileges or higher can exploit this lack of authorization checks to perform actions or access data beyond their intended permissions. The vulnerability is reachable over the network without user interaction. The issue is resolved in version 3.4.2.
Affected products
- Jordy Meow AI Engine (Pro) up to 3.4.2
Timeline
- 2026-02-26: other: Vulnerability reported by researcher
- 2026-03-28: advisory: Patchstack published advisory
- 2026-04-08: disclosed: CVE published