Pricing
Case studies
Login
Start trial
AI Engine
Jordy Meow
Developer
3.4.5
Latest version
100,000
Installations
No date
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
22 patched
16 Mitigation rules
Arbitrary File Upload vulnerability
<= 3.3.2
25/02/2026
Authenticated (Subscriber+) Server-Side Request Forgery vulnerability
<= 3.3.2
28/01/2026
Authenticated (Editor+) Server-Side Request Forgery vulnerability
<= 3.1.8
18/11/2025
Authenticated (Subscriber+) PHP Object Injection via PHAR Deserialization vulnerability
<= 3.1.8
12/11/2025
Unauthenticated Sensitive Information Exposure to Privilege Escalation vulnerability
<= 3.1.3
05/11/2025
Missing Authorization to Unauthenticated Uploaded Files Disclosure And Deletion vulnerability
<= 2.9.5
03/09/2025
Authenticated (Subscriber+) Arbitrary File Upload
2.9.3-2.9.4
30/07/2025
Missing URL Scheme Validation to Authenticated (Subscriber+) Arbitrary File Read via simpleTranscribeAudio and get_audio Functions vulnerability
<= 2.9.4
23/07/2025
Authenticated (Subscriber+) Stored Cross-Site Scripting via `mwai_chatbot` Shortcode `id` Parameter vulnerability
<= 2.8.4
07/07/2025
Insecure OAuth Implementation vulnerability
<= 2.8.4
03/07/2025
Authenticated (Subscriber+) Insufficient Authorization to Privilege Escalation via MCP vulnerability
<= 2.8.3
19/06/2025
Admin+ SQLi vulnerability
< 2.6.5
12/12/2024
Admin+ SQLi vulnerability
< 2.4.8
13/09/2024
Admin+ RCE vulnerability
< 2.5.1
19/08/2024
Server Side Request Forgery (SSRF) vulnerability
<= 2.4.7
22/07/2024
Arbitrary File Upload vulnerability
<= 2.2.63
07/05/2024
Server Side Request Forgery (SSRF) vulnerability
<= 2.1.4
26/03/2024
Arbitrary File Upload vulnerability
<= 2.1.4
26/03/2024
Unauthenticated Stored Cross-Site Scripting vulnerability
<= 2.2.0
04/03/2024
Authenticated (Editor+) Arbitrary File Upload via add_image_from_url vulnerability
<= 2.1.4
06/02/2024
Unauthenticated Arbitrary File Upload vulnerability
<= 1.9.98
09/01/2024
Auth. Stored Cross-Site Scripting (XSS) vulnerability
<= 1.6.82
19/05/2023