PHP Object Injection Vulnerability in AI Engine Plugin for WordPress
CVE-2025-12844
7.1HIGH
What is CVE-2025-12844?
The AI Engine plugin for WordPress is vulnerable to PHP Object Injection due to improper handling of untrusted input in its deserialization processes. Specifically, the functions 'rest_simpleTranscribeAudio' and 'rest_simpleVisionQuery' can be exploited by authenticated users with Subscriber-level access and above. Although no known PHP Object Pollution (POP) chain exists in the vulnerable software alone, an attacker can leverage this vulnerability if combined with additional plugins or themes that do include a POP chain. This could enable the execution of malicious actions like deleting files, retrieving sensitive data, or executing arbitrary code, depending on the available exploits within the environment.
Affected Version(s)
AI Engine * <= 3.1.8