PHP Object Injection Vulnerability in AI Engine Plugin for WordPress
CVE-2025-12844
What is CVE-2025-12844?
The AI Engine plugin for WordPress is vulnerable to PHP Object Injection due to improper handling of untrusted input in its deserialization processes. Specifically, the functions 'rest_simpleTranscribeAudio' and 'rest_simpleVisionQuery' can be exploited by authenticated users with Subscriber-level access and above. Although no known PHP Object Pollution (POP) chain exists in the vulnerable software alone, an attacker can leverage this vulnerability if combined with additional plugins or themes that do include a POP chain. This could enable the execution of malicious actions like deleting files, retrieving sensitive data, or executing arbitrary code, depending on the available exploits within the environment.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AI Engine * <= 3.1.8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved