Etavrian
keyboard_arrow_right Created with Sketch.
News
keyboard_arrow_right Created with Sketch.

Critical AI Engine flaw lets subscribers upload malware - is your WordPress site safe?

Reviewed:
Andrii Daniv
1
min read
Jul 31, 2025
Cracked AI lock with upload arrow and bug warning site admin

Security researchers at Wordfence have disclosed a high-severity flaw in the AI Engine WordPress plugin that lets subscriber-level users upload arbitrary files when the REST API is enabled. The vulnerability affects more than 100,000 websites and was patched on 17 July 2025.

Key details

  • CVSS 3.1 base score: 8.8 (high)
  • Affected versions: 2.9.3 and 2.9.4
  • Exploit requirements: authenticated subscriber account and an active REST API endpoint
  • Root cause: missing file-type validation, enabling remote code execution
  • Fix: version 2.9.5 adds proper validation and server-side request forgery checks
  • Fifth disclosed AI Engine vulnerability in 2025; four others surfaced in June and July

Why it matters

AI Engine integrates generative text, image creation, and audio transcription into WordPress by exposing multiple REST API endpoints. Each endpoint widens the attack surface, and insufficient validation can allow attackers to seize site control or pivot further into the hosting environment.

Plugin security record

Wordfence cataloged nine AI Engine vulnerabilities in 2024, two scoring above 9.0 CVSS. With five issues already disclosed in 2025, the plugin continues to require close security attention.

Recommended action

  • Update to AI Engine 2.9.5 or later via the WordPress dashboard or CLI.
  • Restrict subscriber capabilities where feasible.
  • Audit custom roles and disable unused REST API endpoints.
  • When developing custom code, validate uploads with the wp_check_filetype_and_ext() function.

Sources

Quickly summarize and get insighs with: 
Author
Andrew Daniv, Andrii Daniv
Andrii Daniv
Andrii Daniv is the founder and owner of Etavrian, a performance-driven agency specializing in PPC and SEO services for B2B and e‑commerce businesses.
Reviewed
Andrew Daniv, Andrii Daniv
Andrii Daniv
Andrii Daniv is the founder and owner of Etavrian, a performance-driven agency specializing in PPC and SEO services for B2B and e‑commerce businesses.
Quickly summarize and get insighs with: 
Table of contents