# AI Engine <= 3.8.3 - Authenticated (Contributor+) Missing Authorization to Chatbot Configuration Override via 'mwai_chatbot' Shortcode

- **ID:** WPSEC-2026-0699
- **Plugin:** AI Engine – The Chatbot, AI Framework & MCP for WordPress (`ai-engine`), https://wordpress.org/plugins/ai-engine/
- **Affected versions:** all versions before 3.8.4
- **Fixed in:** 3.8.4 (Update to 3.8.4 or later.)
- **Severity:** Medium 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N)
- **Weakness:** CWE-862
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/ai-engine
- **Fix released:** 2026-10-08
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0699/

## Description

The AI Engine plugin for WordPress is vulnerable to unauthorized modification of chatbot configuration via the mwai_chatbot shortcode in all versions up to, and including, 3.8.3, due to missing authorization when server-side overrides (instructions, model, environment, API key, functions and other server parameters) set in shortcode attributes are saved under the shortcode's custom_id and shared with every visitor of that custom_id, regardless of the capabilities of the post's author. This makes it possible for authenticated attackers, with Contributor-level access and above, to preview a draft containing a shortcode that reuses an existing chatbot's custom_id and replace the prompt, model, environment or API key that the live chatbot uses for site visitors.

## References

- https://wpsec.com/vuln/WPSEC-2026-0699/
- https://plugins.svn.wordpress.org/ai-engine/tags/3.8.4/
- https://wordpress.org/plugins/ai-engine/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0699/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
