HomeSecurityAI Engine: Vulnerability in WordPress plugin puts 100,000 sites at risk

AI Engine: Vulnerability in WordPress plugin puts 100,000 sites at risk

A new serious vulnerability in the popular WordPress plugin AI Engine puts over 100,000 websites at risk , allowing hackers to gain full administrative privileges . The security flaw, codenamed CVE-2025-11749 , has received an extremely high CVSS score of 9.8 , placing it in the most dangerous threat categories.

AI Engine WordPress plugin

How the case began

The issue was discovered by security researcher Emiliano Versini on October 4, 2025. Versini responsibly reported the issue through the Wordfence Bug Bounty, receiving a reward of $2,145 for his contribution to the platform's security.

The vulnerability affects all versions of the plugin up to 3.1.3, exposing critical tokens via the REST API — a component used for communication between the site and external services.

See also: 7 vulnerabilities in GPT-4o and GPT-5 allow 0-Click attacks

WordPress plugin AI Engine: How the dangerous bug works

When website administrators enable the “No-Auth URL” feature in the Model Context Protocol (MCP), the plugin inadvertently exposes bearer tokens via the /wp-json/ REST API index.

These tokens serve as credentials authentication for the MCP integration, which allows AI agents, such as Claude and ChatGPT, to control WordPress sites by executing commands.

AI Engine: Vulnerability in WordPress plugin puts 100,000 sites at risk

Wordfence researchers identified the cause in the plugin's REST API route registration process

The vulnerable code logs No-Auth URL endpoints, without setting the "show_in_index" parameter to false, making these endpoints publicly accessible.

Once attackers extract the exposed bearer token from the API index, they can authenticate to the MCP endpoint and execute commands such as “wp_update_user” to escalate their privileges to administrator level.

See also: Vulnerability in Windows Cloud Files Mini Filter is being actively exploited

What can hackers do with this access?

With full access, an attacker could:

  • Install malicious plugins or backdoors for future attacks,
  • Modify content and introduce spam or phishing campaigns,
  • Redirect visitors to dangerous websites,
  • Even to export user or customer data .

The incident highlights the huge impact that a seemingly small code omission can have on an open source platform like WordPress.

The fix came with version 3.1.4, in which the plugin's creator, Jordy Meow, added the parameter that now hides the endpoints from the public API. At the same time, users are urged to renew their tokens, as the old ones may already have been leaked.

AI Engine: Vulnerability in WordPress plugin puts 100,000 sites at risk

Protection measures and security updates

The Wordfence team acted quickly, releasing firewall rules for Premium, Care, and Response users on October 15, 2025. Free users will receive the same protection on November 14, 2025. These firewall rules detect and block exploit attempts targeting the AI ​​Engine REST API endpoints.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Website administrators are asked to:

  1. Immediately update the plugin to version 3.1.4 or later,
  2. Create new bearer tokens through MCP settings,
  3. Check logs for suspicious REST API actions,
  4. And keep the Wordfence firewall or other reliable security plugin active.

See also: Hackers exploit OneDrive.exe to execute arbitrary code

Another bell for the security of AI plugins

The AI ​​Engine case reveals the growing risks that come with AI-based WordPress plugins. As more and more sites incorporate “smart” features, the attack surface grows.

Experts warn that integrating AI API keys, models, and automations requires careful attention to credential management and endpoint configuration. A simple configuration error can turn into a complete security collapse for a website.

The AI ​​Engine incident serves as a reminder that security in the digital world is never a given. Developers must implement “secure by design” principles, while website administrators must systematically update their plugins.

In the age of artificial intelligence, the ease of integrating smart features should not outweigh the need for security. A neglected token can become the gateway to a full-blown breach.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS