6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Description
The AI Engine plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the rest_list and delete_files functions in all versions up to, and including, 2.9.5. This makes it possible for unauthenticated attackers to list and delete files uploaded by other users.
Basic Information
ID
CVE-2025-8268
Source
Wordfence
Published
Sep 3, 2025 at 20:24
Modified
Sep 3, 2025 at 20:47
Affected Product
Vendor
tigroumeow
Product
AI Engine
Version
*
Affected Versions
tigroumeow AI Engine *
CWE Classification
References
- www.wordfence.com /threat-intel/vulnerabilities/id/be39e24f-d7d7-44db-9ffd-a4605de8e577
- plugins.trac.wordpress.org /browser/ai-engine/tags/2.9.5/classes/modules/files.php
- plugins.trac.wordpress.org /browser/ai-engine/tags/2.9.5/classes/modules/files.php
- plugins.trac.wordpress.org /browser/ai-engine/tags/2.9.5/classes/modules/files.php