WP Clinic
Log in Sign up

CVE · Critical

CVE-2025-11749 — AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.1.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-11749 AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.1.4 Exposure of Sensitive Information to an Unauthorized Actor Critical 9.8 < 3.1.4 3.1.4 2025-11-04

CVE-2025-11749

The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the /mcp/v1/ REST API endpoint that exposes the 'Bearer Token' value when 'No-Auth URL' is enabled. This makes it possible for unauthenticated attackers to extract the bearer token, which can be used to gain access to a valid session and perform many actions like creating a new administrator account, leading to privilege escalation.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.