URL has been copied successfully!
WordPress AI Engine Plugin Bug Allows Remote Code Execution Update Now
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

WordPress AI Engine Plugin Bug Allows Remote Code Execution Update Now

A security flaw affecting over 100,000 WordPress websites has been discovered in the AI Engine plugin, specifically impacting versions 2.9.3 and 2.9.4. The vulnerability, classified as an arbitrary file upload vulnerability, allows authenticated users, starting from subscriber-level access, to upload malicious files and potentially gain remote code execution (RCE) privileges on the server. This type of vulnerability could result in full site compromise.

First seen on thecyberexpress.com

Jump to article: thecyberexpress.com/ai-engine-plugin-vulnerability/

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link