S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Nov 14, 2025

CVE-2025-11749 Scanner

CVE-2025-11749 Scanner - Information Disclosure vulnerability in WordPress AI Engine Plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.5k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-11749
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the /mcp/v1/ REST API endpoint that exposes the 'Bearer Token' value when 'No-Auth URL' is enabled. This makes it possible for unauthenticated attackers to extract the bearer token, which can be used to gain access to a valid session and perform many actions like creating a new administrator account, leading to privilege escalation.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
AI Engine – The Chatbot, AI Framework & MCP for WordPressby tigroumeow
0
Updated Sep 9, 2026View on NVD →
Detail

The WordPress AI Engine Plugin is a popular add-on for WordPress that enhances the website's capabilities by integrating AI functionalities. It is widely used by developers and website administrators to implement AI features easily on WordPress sites. The plugin is designed to be user-friendly and caters to both small and large websites seeking to incorporate artificial intelligence into their content management system. The plugin provides accessibility to advanced AI technologies without requiring extensive coding knowledge, making it a go-to choice for WordPress users. Furthermore, it is maintained and regularly updated, providing consistent improvements and support for users.

The Information Disclosure vulnerability in the WordPress AI Engine Plugin poses significant risks to affected websites. This vulnerability allows unauthorized access to sensitive information, specifically bearer tokens, via REST API endpoints in the plugin. It primarily occurs when the No-Auth URL feature is enabled, leading to potential exposure of sensitive data. Such vulnerabilities can raise concerns over data privacy and integrity, making it crucial to address them promptly. The critical severity of this vulnerability necessitates immediate attention and action to mitigate risks associated with unauthorized data access.

Technical details of the vulnerability reveal that the exposure occurs through REST API endpoints when the No-Auth URL option is activated. As a result, bearer tokens, which are crucial for authentication and authorization processes, are exposed through these endpoints. Indicative endpoints include "/wp-json/mcp/v1", where specific patterns such as "/messages" and "/sse" in API responses are linked to the vulnerability. These details highlight the need for secure API endpoint management to prevent potential security breaches.

Exploiting the Information Disclosure vulnerability could lead to severe consequences, including unauthorized access to sensitive areas of a website, such as admin panels or user data. Malicious actors with access to bearer tokens could impersonate legitimate users or escalate privileges, causing significant disruptions. Furthermore, the exposure of such sensitive information could lead to data breaches, loss of user trust, and potential reputational damage to the affected organizations or individuals. It underscores the importance of robust security practices and timely patching of vulnerabilities.

REFERENCES

Solution Advice
  • Disable the No-Auth URL feature in the AI Engine Plugin settings.
  • Update the WordPress AI Engine Plugin to the latest version as soon as a patch is available.
  • Regularly review API endpoint configurations to ensure they are secure.
  • Implement additional access controls to protect sensitive API endpoints.
  • Monitor for any unusual activities or unauthorized access attempts to the website's backend.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2025-11749 Scanner - Information Disclosure vulnerability in WordPress AI Engine Plugin | S4E