CVE-2025-5071 is a critical vulnerability affecting the AI Engine plugin for WordPress, versions 2.8.0 to 2.8.3. It stems from a missing capability check, allowing authenticated attackers with subscriber-level access or higher to gain full control over the plugin's Management Control Panel (MCP). This flaw enables privilege escalation through user manipulation and unauthorized modification or deletion of posts and comments, leading to significant data integrity and availability risks. With a CVSS score of 8.8 (High), the vulnerability is easily exploitable over the network with low attack complexity. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion, suggesting it is not widely targeted at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.8.0, < 2.8.4CPE matchmatch criteria | cpe:2.3:a:meowapps:ai_engine:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.