PHP Object Injection Vulnerability in AI Engine Plugin for WordPress
CVE-2025-12844

7.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
13 November 2025

What is CVE-2025-12844?

The AI Engine plugin for WordPress is vulnerable to PHP Object Injection due to improper handling of untrusted input in its deserialization processes. Specifically, the functions 'rest_simpleTranscribeAudio' and 'rest_simpleVisionQuery' can be exploited by authenticated users with Subscriber-level access and above. Although no known PHP Object Pollution (POP) chain exists in the vulnerable software alone, an attacker can leverage this vulnerability if combined with additional plugins or themes that do include a POP chain. This could enable the execution of malicious actions like deleting files, retrieving sensitive data, or executing arbitrary code, depending on the available exploits within the environment.

Affected Version(s)

AI Engine * <= 3.1.8

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ISMAILSHADOW
.
CVE-2025-12844 : PHP Object Injection Vulnerability in AI Engine Plugin for WordPress