Close Menu
Spicy Creator Tips —Spicy Creator Tips —

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Philadelphia Morning Anchor Mike Jerrick to Host Own Late-Night Talk Show

    August 28, 2025

    WhatsApp’s AI can now turn your messages into awkward dad jokes

    August 28, 2025

    Sonos headphones and speakers are up to 25 percent off for Labor Day

    August 28, 2025
    Facebook X (Twitter) Instagram
    Spicy Creator Tips —Spicy Creator Tips —
    Trending
    • Philadelphia Morning Anchor Mike Jerrick to Host Own Late-Night Talk Show
    • WhatsApp’s AI can now turn your messages into awkward dad jokes
    • Sonos headphones and speakers are up to 25 percent off for Labor Day
    • IBC2025: Mavis Camera app now supports NDI by Jose Antunes
    • Accelerant Revenue Jumps 68% in Q2
    • Minister refuses to deny reports Rachel Reeves considering tax increase for landlords in budget – UK politics live | Politics
    • Ganesh Chaturthi 2025: Fashion tips to be ready for puja and pandal-hopping | Fashion Trends
    • How Often Should You Post on LinkedIn in 2025? Data From 2 Million+ Posts
    Facebook X (Twitter) Instagram
    • Home
    • Ideas
    • Editing
    • Equipment
    • Growth
    • Retention
    • Stories
    • Strategy
    • Engagement
    • Modeling
    • Captions
    Spicy Creator Tips —Spicy Creator Tips —
    Home»Engagement»WordPress AI Engine Plugin Vulnerability Affects Up To 100,000 Websites
    Engagement

    WordPress AI Engine Plugin Vulnerability Affects Up To 100,000 Websites

    spicycreatortips_18q76aBy spicycreatortips_18q76aJuly 30, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
    WordPress AI Engine Plugin Vulnerability Affects Up To 100,000 Websites
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A safety advisory was issued for the AI Engine WordPress plugin, put in on over 100,000 web sites, the fourth one this month. Rated 8.8, this vulnerability permits attackers with solely subscriber-level authentication to add malicious recordsdata when the REST API is enabled.

    AI Engine Plugin: Fifth Vulnerability In 2025

    That is the fourth vulnerability found within the AI Engine plugin in July, following the primary one of many yr found in June, making a complete of 5 vulnerabilities found within the plugin thus far in 2025. There have been 9 vulnerabilities found in 2024, one among which was rated 9.8 as a result of it enabled unauthenticated attackers to add malicious recordsdata, plus one other rated 9.1 that additionally enabled arbitrary uploads.

    Authenticated (Subscriber+) Arbitrary File Add

    The most recent vulnerability permits authenticated file uploads. What makes this exploit extra harmful is that it requires solely subscriber-level authentication for an attacker to benefit from the safety weak spot. That isn’t as unhealthy as a vulnerability that doesn’t require authentication, but it surely’s nonetheless rated 8.8 on a scale of 1 to 10.

    Wordfence describes the vulnerability as being attributable to lacking file sort validation in a perform associated to the REST API in variations 2.9.3 and a couple of.9.4.

    File sort validation is a safety measure usually used inside WordPress to ensure that the content material of a file matches the kind of file being uploaded to the web site.

    In line with Wordfence:

    “This makes it attainable for authenticated attackers, with Subscriber-level entry and above, to add arbitrary recordsdata on the affected web site’s server when the REST API is enabled, which can make distant code execution attainable.”

    Customers of the AI Engine plugin are really useful updating their plugin to the most recent model, 2.9.5, or a more moderen model.

    The plugin changelog for model 2.9.5 shares what was up to date:

    “Repair: Resolved a safety subject associated to SSRF by validating URL schemes in audio transcription and sanitizing REST API parameters to forestall API key misuse.

    Repair: Corrected a crucial safety vulnerability that allowed unauthorized file uploads by including strict file sort validation to forestall PHP execution.”

    Featured Picture by Shutterstock/Jiri Hera

    affects Engine Plugin Vulnerability websites WordPress
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    spicycreatortips_18q76a
    • Website

    Related Posts

    Philadelphia Morning Anchor Mike Jerrick to Host Own Late-Night Talk Show

    August 28, 2025

    Top breast implants in the world: What you need to know

    August 28, 2025

    New Strategies To Gain Local Search Visibility

    August 28, 2025

    WhatsApp Adds AI-Powered Suggestions to Improve Your DMs

    August 28, 2025

    WAPT Anchor Celeste Wilson Dies Suddenly at 42

    August 28, 2025

    Developers warned: Poor drainage could stall new build approvals

    August 28, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Don't Miss
    Engagement

    Philadelphia Morning Anchor Mike Jerrick to Host Own Late-Night Talk Show

    August 28, 2025

    Mike Jerrick will host his personal late evening speak present referred to as, oddly sufficient,…

    WhatsApp’s AI can now turn your messages into awkward dad jokes

    August 28, 2025

    Sonos headphones and speakers are up to 25 percent off for Labor Day

    August 28, 2025

    IBC2025: Mavis Camera app now supports NDI by Jose Antunes

    August 28, 2025
    Our Picks

    Four ways to be more selfish at work

    June 18, 2025

    How to Create a Seamless Instagram Carousel Post

    June 18, 2025

    Up First from NPR : NPR

    June 18, 2025

    Meta Plans to Release New Oakley, Prada AI Smart Glasses

    June 18, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    About Us

    Welcome to SpicyCreatorTips.com — your go-to hub for leveling up your content game!

    At Spicy Creator Tips, we believe that every creator has the potential to grow, engage, and thrive with the right strategies and tools.
    We're accepting new partnerships right now.

    Our Picks

    Philadelphia Morning Anchor Mike Jerrick to Host Own Late-Night Talk Show

    August 28, 2025

    WhatsApp’s AI can now turn your messages into awkward dad jokes

    August 28, 2025
    Recent Posts
    • Philadelphia Morning Anchor Mike Jerrick to Host Own Late-Night Talk Show
    • WhatsApp’s AI can now turn your messages into awkward dad jokes
    • Sonos headphones and speakers are up to 25 percent off for Labor Day
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Disclaimer
    • Get In Touch
    • Privacy Policy
    • Terms and Conditions
    © 2025 spicycreatortips. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.