Description
The AI Engine plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the rest_list and delete_files functions in all versions up to, and including, 2.9.5. This makes it possible for unauthenticated attackers to list and delete files uploaded by other users.
Problem types
Product status
*
Timeline
2025-07-14: | Discovered |
2025-07-27: | Vendor Notified |
2025-09-03: | Disclosed |
Credits
ISMAILSHADOW
References
www.wordfence.com/...-d7d7-44db-9ffd-a4605de8e577?source=cve
plugins.trac.wordpress.org/....9.5/classes/modules/files.php
plugins.trac.wordpress.org/....9.5/classes/modules/files.php
plugins.trac.wordpress.org/....9.5/classes/modules/files.php