Close Menu
SteamyMarketing.com
    What's Hot

    Bharti Singh claps back at trolls criticising her for resuming work 12 days after delivery: ‘Uncle log the saare’; psychotherapist weighs in | Lifestyle News

    August 28, 2025

    West Midlands delegation begins Birmingham 2027 promotion

    August 28, 2025

    A rare Jurassic-era fossil has been discovered in India; know all about it | Pets-animals News

    August 28, 2025
    Facebook X (Twitter) Instagram
    Trending
    • Bharti Singh claps back at trolls criticising her for resuming work 12 days after delivery: ‘Uncle log the saare’; psychotherapist weighs in | Lifestyle News
    • West Midlands delegation begins Birmingham 2027 promotion
    • A rare Jurassic-era fossil has been discovered in India; know all about it | Pets-animals News
    • Google Launches Image-to-Video Tool for Product Promotions
    • ITS ATLANTA VIDEO: ADEC announces new TDC3X Multiradar detector
    • ‘Being a fitness freak, it came to me as big news’: Actor Celina Jaitly swears by this ‘medically-backed’ way to take care of her ‘second heart’ | Fitness News
    • Instagram Launches Video Education Series for Edits App
    • ITSWC 2025: Thursday sessions guide
    Thursday, August 28
    SteamyMarketing.com
    Facebook X (Twitter) Instagram
    • Home
    • Affiliate
    • SEO
    • Monetize
    • Content
    • Email
    • Funnels
    • Legal
    • Paid Ads
    • Modeling
    • Traffic
    SteamyMarketing.com
    • About
    • Get In Touch
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    Home»SEO»WordPress AI Engine Plugin Vulnerability Affects Up To 100,000 Websites
    SEO

    WordPress AI Engine Plugin Vulnerability Affects Up To 100,000 Websites

    steamymarketing_jyqpv8By steamymarketing_jyqpv8July 30, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
    WordPress AI Engine Plugin Vulnerability Affects Up To 100,000 Websites
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    A safety advisory was issued for the AI Engine WordPress plugin, put in on over 100,000 web sites, the fourth one this month. Rated 8.8, this vulnerability allows attackers with solely subscriber-level authentication to add malicious information when the REST API is enabled.

    AI Engine Plugin: Fifth Vulnerability In 2025

    That is the fourth vulnerability found within the AI Engine plugin in July, following the primary one of many yr found in June, making a complete of 5 vulnerabilities found within the plugin up to now in 2025. There have been 9 vulnerabilities found in 2024, one among which was rated 9.8 as a result of it enabled unauthenticated attackers to add malicious information, plus one other rated 9.1 that additionally enabled arbitrary uploads.

    Authenticated (Subscriber+) Arbitrary File Add

    The most recent vulnerability allows authenticated file uploads. What makes this exploit extra harmful is that it requires solely subscriber-level authentication for an attacker to reap the benefits of the safety weak spot. That isn’t as dangerous as a vulnerability that doesn’t require authentication, however it’s nonetheless rated 8.8 on a scale of 1 to 10.

    Wordfence describes the vulnerability as being resulting from lacking file sort validation in a operate associated to the REST API in variations 2.9.3 and a couple of.9.4.

    File sort validation is a safety measure sometimes used inside WordPress to be sure that the content material of a file matches the kind of file being uploaded to the web site.

    In line with Wordfence:

    “This makes it doable for authenticated attackers, with Subscriber-level entry and above, to add arbitrary information on the affected web site’s server when the REST API is enabled, which can make distant code execution doable.”

    Customers of the AI Engine plugin are beneficial updating their plugin to the most recent model, 2.9.5, or a more recent model.

    The plugin changelog for model 2.9.5 shares what was up to date:

    “Repair: Resolved a safety challenge associated to SSRF by validating URL schemes in audio transcription and sanitizing REST API parameters to forestall API key misuse.

    Repair: Corrected a crucial safety vulnerability that allowed unauthorized file uploads by including strict file sort validation to forestall PHP execution.”

    Featured Picture by Shutterstock/Jiri Hera

    Affects Engine Plugin Vulnerability Websites WordPress
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleGoogle to Use Machine Learning to Estimate Users’ Age and Block Them From Restricted Content and Ads
    Next Article Federal Reserve Holds Rates Steady, Fifth-Straight Time
    steamymarketing_jyqpv8
    • Website

    Related Posts

    New Strategies To Gain Local Search Visibility

    August 28, 2025

    Professionals Trust Their Networks Over AI & Search

    August 27, 2025

    Real-World Uses You Need to Try

    August 27, 2025

    What To Do When the Click Disappears: Surviving SEO In The AI-Driven SERP via @sejournal, @AdamHeitzman

    August 27, 2025

    Why The C-Suite Must Take Web Effectiveness Seriously

    August 27, 2025

    Perplexity’s Discover Pages Offer A Surprising SEO Insight

    August 27, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Economy News

    Bharti Singh claps back at trolls criticising her for resuming work 12 days after delivery: ‘Uncle log the saare’; psychotherapist weighs in | Lifestyle News

    By steamymarketing_jyqpv8August 28, 2025

    Comic and host Bharti Singh just lately addressed the trolling she confronted after returning to…

    West Midlands delegation begins Birmingham 2027 promotion

    August 28, 2025

    A rare Jurassic-era fossil has been discovered in India; know all about it | Pets-animals News

    August 28, 2025
    Top Trending

    Passion as a Compass: Finding Your Ideal Educational Direction

    By steamymarketing_jyqpv8June 18, 2025

    Discovering one’s path in life is usually navigated utilizing ardour as a…

    Disbarment recommended for ex-Trump lawyer Eastman by State Bar Court of California panel

    By steamymarketing_jyqpv8June 18, 2025

    House Each day Information Disbarment beneficial for ex-Trump lawyer… Ethics Disbarment beneficial…

    Why Social Media Belongs in Your Sales Funnel

    By steamymarketing_jyqpv8June 18, 2025

    TikTok, Instagram, LinkedIn, and Fb: these platforms may not instantly come to…

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Facebook X (Twitter) Pinterest Vimeo WhatsApp TikTok Instagram

    News

    • Affiliate
    • Content
    • Email
    • Funnels
    • Legal

    Company

    • Monetize
    • Paid Ads
    • SEO
    • Social Ads
    • Traffic
    Recent Posts
    • Bharti Singh claps back at trolls criticising her for resuming work 12 days after delivery: ‘Uncle log the saare’; psychotherapist weighs in | Lifestyle News
    • West Midlands delegation begins Birmingham 2027 promotion

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2025 steamymarketing. Designed by pro.
    • About
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.