Close Menu
Spicy Creator Tips —Spicy Creator Tips —

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The hurdles to Perplexity becoming the publisher-friendly LLM

    August 28, 2025

    WAPT Anchor Celeste Wilson Dies Suddenly at 42

    August 28, 2025

    My essential checklist for engaging character art

    August 28, 2025
    Facebook X (Twitter) Instagram
    Spicy Creator Tips —Spicy Creator Tips —
    Trending
    • The hurdles to Perplexity becoming the publisher-friendly LLM
    • WAPT Anchor Celeste Wilson Dies Suddenly at 42
    • My essential checklist for engaging character art
    • The Best Labor Day Weekend Sales
    • FUJIFILM Middle East Short Film Festival Announced – Submit Your Film by September 15, 2025
    • Nvidia’s Earnings Pull Just Ahead of Estimates
    • I never knew my phone camera could do this until I tried it
    • How We Test Projectors | PCMag
    Facebook X (Twitter) Instagram
    • Home
    • Ideas
    • Editing
    • Equipment
    • Growth
    • Retention
    • Stories
    • Strategy
    • Engagement
    • Modeling
    • Captions
    Spicy Creator Tips —Spicy Creator Tips —
    Home»Engagement»WordPress AI Engine Plugin Vulnerability Affects Up To 100,000 Websites
    Engagement

    WordPress AI Engine Plugin Vulnerability Affects Up To 100,000 Websites

    spicycreatortips_18q76aBy spicycreatortips_18q76aJuly 30, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
    WordPress AI Engine Plugin Vulnerability Affects Up To 100,000 Websites
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A safety advisory was issued for the AI Engine WordPress plugin, put in on over 100,000 web sites, the fourth one this month. Rated 8.8, this vulnerability permits attackers with solely subscriber-level authentication to add malicious recordsdata when the REST API is enabled.

    AI Engine Plugin: Fifth Vulnerability In 2025

    That is the fourth vulnerability found within the AI Engine plugin in July, following the primary one of many yr found in June, making a complete of 5 vulnerabilities found within the plugin thus far in 2025. There have been 9 vulnerabilities found in 2024, one among which was rated 9.8 as a result of it enabled unauthenticated attackers to add malicious recordsdata, plus one other rated 9.1 that additionally enabled arbitrary uploads.

    Authenticated (Subscriber+) Arbitrary File Add

    The most recent vulnerability permits authenticated file uploads. What makes this exploit extra harmful is that it requires solely subscriber-level authentication for an attacker to benefit from the safety weak spot. That isn’t as unhealthy as a vulnerability that doesn’t require authentication, but it surely’s nonetheless rated 8.8 on a scale of 1 to 10.

    Wordfence describes the vulnerability as being attributable to lacking file sort validation in a perform associated to the REST API in variations 2.9.3 and a couple of.9.4.

    File sort validation is a safety measure usually used inside WordPress to ensure that the content material of a file matches the kind of file being uploaded to the web site.

    In line with Wordfence:

    “This makes it attainable for authenticated attackers, with Subscriber-level entry and above, to add arbitrary recordsdata on the affected web site’s server when the REST API is enabled, which can make distant code execution attainable.”

    Customers of the AI Engine plugin are really useful updating their plugin to the most recent model, 2.9.5, or a more moderen model.

    The plugin changelog for model 2.9.5 shares what was up to date:

    “Repair: Resolved a safety subject associated to SSRF by validating URL schemes in audio transcription and sanitizing REST API parameters to forestall API key misuse.

    Repair: Corrected a crucial safety vulnerability that allowed unauthorized file uploads by including strict file sort validation to forestall PHP execution.”

    Featured Picture by Shutterstock/Jiri Hera

    affects Engine Plugin Vulnerability websites WordPress
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    spicycreatortips_18q76a
    • Website

    Related Posts

    WAPT Anchor Celeste Wilson Dies Suddenly at 42

    August 28, 2025

    Developers warned: Poor drainage could stall new build approvals

    August 28, 2025

    Google Brings Loyalty Offerings To Merchant Retailers

    August 28, 2025

    Meta Shares Latest Data on Policy Enforcements and Content Trends

    August 28, 2025

    KABC Morning Anchor Leslie Sykes Announces Retirement

    August 28, 2025

    Why You Should Own Multiple Smartwatch Straps

    August 28, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Don't Miss
    Retention

    The hurdles to Perplexity becoming the publisher-friendly LLM

    August 28, 2025

    This week’s Media Briefing seems to be at Perplexity’s newest writer income share mannequin, and…

    WAPT Anchor Celeste Wilson Dies Suddenly at 42

    August 28, 2025

    My essential checklist for engaging character art

    August 28, 2025

    The Best Labor Day Weekend Sales

    August 28, 2025
    Our Picks

    Four ways to be more selfish at work

    June 18, 2025

    How to Create a Seamless Instagram Carousel Post

    June 18, 2025

    Up First from NPR : NPR

    June 18, 2025

    Meta Plans to Release New Oakley, Prada AI Smart Glasses

    June 18, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    About Us

    Welcome to SpicyCreatorTips.com — your go-to hub for leveling up your content game!

    At Spicy Creator Tips, we believe that every creator has the potential to grow, engage, and thrive with the right strategies and tools.
    We're accepting new partnerships right now.

    Our Picks

    The hurdles to Perplexity becoming the publisher-friendly LLM

    August 28, 2025

    WAPT Anchor Celeste Wilson Dies Suddenly at 42

    August 28, 2025
    Recent Posts
    • The hurdles to Perplexity becoming the publisher-friendly LLM
    • WAPT Anchor Celeste Wilson Dies Suddenly at 42
    • My essential checklist for engaging character art
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Disclaimer
    • Get In Touch
    • Privacy Policy
    • Terms and Conditions
    © 2025 spicycreatortips. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.