AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
CVE-2025-11749

9.8CRITICAL

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
5 November 2025

What is CVE-2025-11749?

The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the /mcp/v1/ REST API endpoint that exposes the 'Bearer Token' value when 'No-Auth URL' is enabled. This makes it possible for unauthenticated attackers to extract the bearer token, which can be used to gain access to a valid session and perform many actions like creating a new administrator account, leading to privilege escalation.

Affected Version(s)

AI Engine * <= 3.1.3

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Emiliano Versini
.
CVE-2025-11749 : Sensitive Information Exposure in AI Engine Plugin for WordPress