Close Menu
Spicy Creator Tips —Spicy Creator Tips —

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    This week in business: Markets, machines, and mosquitoes

    October 25, 2025

    Give yourself permission to be creative | Ethan Hawke (re-release)

    October 25, 2025

    Try This One-Minute Test to Uncover Hidden Health Risks

    October 25, 2025
    Facebook X (Twitter) Instagram
    Spicy Creator Tips —Spicy Creator Tips —
    Trending
    • This week in business: Markets, machines, and mosquitoes
    • Give yourself permission to be creative | Ethan Hawke (re-release)
    • Try This One-Minute Test to Uncover Hidden Health Risks
    • Serena Williams’ Red Pumps Turn Heads at the Princesa De Asturias Awards Ceremony
    • 9 Films That Changed the Oscars Forever
    • Master Buffett & Munger’s Proven Strategy to Identify Long-Term Stock Winners
    • Labour’s new deputy leader says party must pay more heed to its members | Lucy Powell
    • Colorfront Transkoder receives HDR Vivid Color-Grading Award by Jose Antunes
    Facebook X (Twitter) Instagram
    • Home
    • Ideas
    • Editing
    • Equipment
    • Growth
    • Retention
    • Stories
    • Strategy
    • Engagement
    • Modeling
    • Captions
    Spicy Creator Tips —Spicy Creator Tips —
    Home»Engagement»WordPress AI Engine Plugin Vulnerability Affects Up To 100,000 Websites
    Engagement

    WordPress AI Engine Plugin Vulnerability Affects Up To 100,000 Websites

    spicycreatortips_18q76aBy spicycreatortips_18q76aJuly 30, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
    WordPress AI Engine Plugin Vulnerability Affects Up To 100,000 Websites
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A safety advisory was issued for the AI Engine WordPress plugin, put in on over 100,000 web sites, the fourth one this month. Rated 8.8, this vulnerability permits attackers with solely subscriber-level authentication to add malicious recordsdata when the REST API is enabled.

    AI Engine Plugin: Fifth Vulnerability In 2025

    That is the fourth vulnerability found within the AI Engine plugin in July, following the primary one of many yr found in June, making a complete of 5 vulnerabilities found within the plugin thus far in 2025. There have been 9 vulnerabilities found in 2024, one among which was rated 9.8 as a result of it enabled unauthenticated attackers to add malicious recordsdata, plus one other rated 9.1 that additionally enabled arbitrary uploads.

    Authenticated (Subscriber+) Arbitrary File Add

    The most recent vulnerability permits authenticated file uploads. What makes this exploit extra harmful is that it requires solely subscriber-level authentication for an attacker to benefit from the safety weak spot. That isn’t as unhealthy as a vulnerability that doesn’t require authentication, but it surely’s nonetheless rated 8.8 on a scale of 1 to 10.

    Wordfence describes the vulnerability as being attributable to lacking file sort validation in a perform associated to the REST API in variations 2.9.3 and a couple of.9.4.

    File sort validation is a safety measure usually used inside WordPress to ensure that the content material of a file matches the kind of file being uploaded to the web site.

    In line with Wordfence:

    “This makes it attainable for authenticated attackers, with Subscriber-level entry and above, to add arbitrary recordsdata on the affected web site’s server when the REST API is enabled, which can make distant code execution attainable.”

    Customers of the AI Engine plugin are really useful updating their plugin to the most recent model, 2.9.5, or a more moderen model.

    The plugin changelog for model 2.9.5 shares what was up to date:

    “Repair: Resolved a safety subject associated to SSRF by validating URL schemes in audio transcription and sanitizing REST API parameters to forestall API key misuse.

    Repair: Corrected a crucial safety vulnerability that allowed unauthorized file uploads by including strict file sort validation to forestall PHP execution.”

    Featured Picture by Shutterstock/Jiri Hera

    affects Engine Plugin Vulnerability websites WordPress
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    spicycreatortips_18q76a
    • Website

    Related Posts

    How And Why Google Rewrites Your Hard-Earned Headlines

    October 23, 2025

    Snapchat Expands Access to its Open Prompt AI Lens

    October 23, 2025

    Could the Next Hit Podcaster Be… Your CFO?

    October 23, 2025

    YouTube Expands Likeness Detection To All Monetized Channels

    October 23, 2025

    Reddit Launches Legal Action to Block AI Companies from Scraping its Data

    October 23, 2025

    ABC and CBS Gain Viewers

    October 22, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Don't Miss
    Growth

    This week in business: Markets, machines, and mosquitoes

    October 25, 2025

    This week, tech firms had been both melting down in actual time or promising a…

    Give yourself permission to be creative | Ethan Hawke (re-release)

    October 25, 2025

    Try This One-Minute Test to Uncover Hidden Health Risks

    October 25, 2025

    Serena Williams’ Red Pumps Turn Heads at the Princesa De Asturias Awards Ceremony

    October 25, 2025
    Our Picks

    Four ways to be more selfish at work

    June 18, 2025

    How to Create a Seamless Instagram Carousel Post

    June 18, 2025

    Up First from NPR : NPR

    June 18, 2025

    Meta Plans to Release New Oakley, Prada AI Smart Glasses

    June 18, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    About Us

    Welcome to SpicyCreatorTips.com — your go-to hub for leveling up your content game!

    At Spicy Creator Tips, we believe that every creator has the potential to grow, engage, and thrive with the right strategies and tools.
    We're accepting new partnerships right now.

    Our Picks

    This week in business: Markets, machines, and mosquitoes

    October 25, 2025

    Give yourself permission to be creative | Ethan Hawke (re-release)

    October 25, 2025
    Recent Posts
    • This week in business: Markets, machines, and mosquitoes
    • Give yourself permission to be creative | Ethan Hawke (re-release)
    • Try This One-Minute Test to Uncover Hidden Health Risks
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Disclaimer
    • Get In Touch
    • Privacy Policy
    • Terms and Conditions
    © 2025 spicycreatortips. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.