CyberRota Analysis
AI-GeneratedThe AI Engine WordPress plugin prior to version 3.5.5 is vulnerable due to inadequate verification of user ownership for chatbot conversations, allowing subscribers to access and potentially hijack private conversations of other users. This could lead to unauthorized disclosure of sensitive information and compromise user privacy. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, allowing users with subscriber-level access to read other users' private conversations and take over their conversation records when the discussions feature is enabled.