Category: Plugin vulnerability
-
Vulnerabiltiy in AI Engine for WordPress plugin
In July 2025, the Wordfence security team identified a critical arbitrary file upload vulnerability in the AI Engine plugin for WordPress, affecting approximately 100,000 active installations. This flaw allowed attackers to upload arbitrary files (e.g., PHP) without authentication, potentially leading…