Close Menu
SteamyMarketing.com
    What's Hot

    Why Marketing Agencies Are Struggling in 2025

    August 28, 2025

    Wilmington Anchor Kim Ratcliff Reveals Cancer Diagnosis

    August 28, 2025

    How One Man Conquered the World’s Toughest Peaks — and Built a Brand Every Founder Should Study

    August 28, 2025
    Facebook X (Twitter) Instagram
    Trending
    • Why Marketing Agencies Are Struggling in 2025
    • Wilmington Anchor Kim Ratcliff Reveals Cancer Diagnosis
    • How One Man Conquered the World’s Toughest Peaks — and Built a Brand Every Founder Should Study
    • Fox Weather Gets a Brand Refresh Ahead of Fourth Anniversary
    • 5 style icons from Indian television whose wardrobe you could steal from even now | Fashion News
    • Trump’s plan to penalize states using cashless bail is unconstitutional and unnecessary, critics say
    • Want to Sell More? Make Your Team Less Competitive, Not More
    • Coca-Cola Claimed Christmas. Now Fanta Wants Halloween.
    Thursday, August 28
    SteamyMarketing.com
    Facebook X (Twitter) Instagram
    • Home
    • Affiliate
    • SEO
    • Monetize
    • Content
    • Email
    • Funnels
    • Legal
    • Paid Ads
    • Modeling
    • Traffic
    SteamyMarketing.com
    • About
    • Get In Touch
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    Home»SEO»WordPress AI Engine Plugin Vulnerability Affects Up To 100,000 Websites
    SEO

    WordPress AI Engine Plugin Vulnerability Affects Up To 100,000 Websites

    steamymarketing_jyqpv8By steamymarketing_jyqpv8July 30, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
    WordPress AI Engine Plugin Vulnerability Affects Up To 100,000 Websites
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    A safety advisory was issued for the AI Engine WordPress plugin, put in on over 100,000 web sites, the fourth one this month. Rated 8.8, this vulnerability allows attackers with solely subscriber-level authentication to add malicious information when the REST API is enabled.

    AI Engine Plugin: Fifth Vulnerability In 2025

    That is the fourth vulnerability found within the AI Engine plugin in July, following the primary one of many yr found in June, making a complete of 5 vulnerabilities found within the plugin up to now in 2025. There have been 9 vulnerabilities found in 2024, one among which was rated 9.8 as a result of it enabled unauthenticated attackers to add malicious information, plus one other rated 9.1 that additionally enabled arbitrary uploads.

    Authenticated (Subscriber+) Arbitrary File Add

    The most recent vulnerability allows authenticated file uploads. What makes this exploit extra harmful is that it requires solely subscriber-level authentication for an attacker to reap the benefits of the safety weak spot. That isn’t as dangerous as a vulnerability that doesn’t require authentication, however it’s nonetheless rated 8.8 on a scale of 1 to 10.

    Wordfence describes the vulnerability as being resulting from lacking file sort validation in a operate associated to the REST API in variations 2.9.3 and a couple of.9.4.

    File sort validation is a safety measure sometimes used inside WordPress to be sure that the content material of a file matches the kind of file being uploaded to the web site.

    In line with Wordfence:

    “This makes it doable for authenticated attackers, with Subscriber-level entry and above, to add arbitrary information on the affected web site’s server when the REST API is enabled, which can make distant code execution doable.”

    Customers of the AI Engine plugin are beneficial updating their plugin to the most recent model, 2.9.5, or a more recent model.

    The plugin changelog for model 2.9.5 shares what was up to date:

    “Repair: Resolved a safety challenge associated to SSRF by validating URL schemes in audio transcription and sanitizing REST API parameters to forestall API key misuse.

    Repair: Corrected a crucial safety vulnerability that allowed unauthorized file uploads by including strict file sort validation to forestall PHP execution.”

    Featured Picture by Shutterstock/Jiri Hera

    Affects Engine Plugin Vulnerability Websites WordPress
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleGoogle to Use Machine Learning to Estimate Users’ Age and Block Them From Restricted Content and Ads
    Next Article Federal Reserve Holds Rates Steady, Fifth-Straight Time
    steamymarketing_jyqpv8
    • Website

    Related Posts

    SEO Has Been Tactical For 20 Years. GenAI Forces The Strategy Question

    August 28, 2025

    How Do You Prioritize Technical SEO Fixes?

    August 28, 2025

    WordPress Trademark Applications Rejected By USPTO

    August 28, 2025

    New Strategies To Gain Local Search Visibility

    August 28, 2025

    Professionals Trust Their Networks Over AI & Search

    August 27, 2025

    Real-World Uses You Need to Try

    August 27, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Economy News

    Why Marketing Agencies Are Struggling in 2025

    By steamymarketing_jyqpv8August 28, 2025

    Opinions expressed by Entrepreneur contributors are their very own. I run a boutique advertising and…

    Wilmington Anchor Kim Ratcliff Reveals Cancer Diagnosis

    August 28, 2025

    How One Man Conquered the World’s Toughest Peaks — and Built a Brand Every Founder Should Study

    August 28, 2025
    Top Trending

    Passion as a Compass: Finding Your Ideal Educational Direction

    By steamymarketing_jyqpv8June 18, 2025

    Discovering one’s path in life is usually navigated utilizing ardour as a…

    Disbarment recommended for ex-Trump lawyer Eastman by State Bar Court of California panel

    By steamymarketing_jyqpv8June 18, 2025

    House Each day Information Disbarment beneficial for ex-Trump lawyer… Ethics Disbarment beneficial…

    Why Social Media Belongs in Your Sales Funnel

    By steamymarketing_jyqpv8June 18, 2025

    TikTok, Instagram, LinkedIn, and Fb: these platforms may not instantly come to…

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Facebook X (Twitter) Pinterest Vimeo WhatsApp TikTok Instagram

    News

    • Affiliate
    • Content
    • Email
    • Funnels
    • Legal

    Company

    • Monetize
    • Paid Ads
    • SEO
    • Social Ads
    • Traffic
    Recent Posts
    • Why Marketing Agencies Are Struggling in 2025
    • Wilmington Anchor Kim Ratcliff Reveals Cancer Diagnosis

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2025 steamymarketing. Designed by pro.
    • About
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.