What happened
A multi-stage chain in the AI Engine chatbot plugin: chat-submit denylist bypass → forged PHP error-log injection → indirect prompt injection into the AI prompt → unescaped dashboard rendering (stored XSS). Unauthenticated attackers can stage content that executes in the browser whenever an administrator loads the WordPress dashboard and can influence what the site's AI assistant receives as context.
Why it matters
It is a rare dual-class finding: an unauthenticated indirect prompt-injection path that seeds attacker text into the LLM's context via log poisoning (CWE-1427), plus a stored XSS hitting the admin. For defenders it shows WordPress AI plugins can be weaponized both to poison AI context and to hijack the admin session.
Attack vector
An unauthenticated caller submits a crafted chat request whose model string is canonicalized past a denylist (e.g. 'model ' → 'model'), injecting CR/LF into the query; the resulting exception message is written verbatim to the PHP error log, forging a log line that the plugin's own error-log parser later feeds into the AI prompt (indirect prompt injection, CWE-1427) and whose JSON is rendered unsanitized into the dashboard advisor widget (stored XSS on admin access).
Affected systems
AI Engine – The Chatbot, AI Framework & MCP for WordPress ≤ 3.8.0
Mitigation
Update AI Engine beyond 3.8.0 (plugin vendor MustUsePlugins / MWAI MeowKit patched release); harden PHP error-log write access meanwhile