WordPress AI Engine Plugin Missing Capability Check Vulnerability Allowing Unauthorized File Deletion

Vulnerability

A vulnerability exists in the AI Engine plugin for WordPress, in all versions through 2.9.5, due to a missing capability check. This flaw allows unauthenticated users to access the 'rest_list' and 'delete_files' functions, enabling them to list and delete files uploaded by other users.

Impact

Exploitation of this vulnerability could lead to unauthorized deletion of files uploaded by users.

Reproduction

The vulnerability can be reproduced by sending a POST request to the '/files/list' endpoint without authentication. This will return a list of files uploaded by users. To delete a file, send a POST request to the '/files/delete' endpoint with the file's reference ID, also without authentication.

Remediation

Users are advised to update the AI Engine plugin to version 2.9.6 or later.

Added: Sep 3, 2025, 9:19 PM
Updated: Sep 3, 2025, 9:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
8.4
remediation
7.7
relevance
0.5
threat
4.8
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.