CVE-2025-11749: AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the /mcp/v1/ REST API endpoint that exposes the 'Bearer Token' value when 'No-Auth URL' is enabled. This makes it possible for unauthenticated attackers to extract the bearer token, which can be used to gain access to a valid session and perform many actions like creating a new administrator account, leading to privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11749?
CVE-2025-11749 is classified as a high severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2025-11749?
To fix CVE-2025-11749, update the AI Engine plugin to version 3.1.4 or later.
What versions of the AI Engine are affected by CVE-2025-11749?
All versions of the AI Engine plugin up to and including 3.1.3 are affected by CVE-2025-11749.
What type of exposure does CVE-2025-11749 involve?
CVE-2025-11749 involves the exposure of sensitive information, specifically the 'Bearer Token' value.
Does CVE-2025-11749 require authentication to exploit?
No, CVE-2025-11749 can be exploited by unauthenticated attackers when 'No-Auth URL' is enabled.