100,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in AI Engine WordPress Plugin
Latest Reports: • WordPress Vulnerability Reports by Wordfence
Blog Post: https://www.wordfence.com/blog/2025/0...
🛡️ Get Wordfence: https://www.wordfence.com/products/pr...
🔵 Try Wordfence Central - https://www.wordfence.com/help/central/
⭐ Wordfence is Trusted by over 5 Million Websites
On July 18th, 2025, we received a submission for an Arbitrary File Upload vulnerability in AI Engine, a WordPress plugin with more than 100,000 active installations. This vulnerability can be used by authenticated attackers, with subscriber-level access and above, to upload arbitrary files to a vulnerable site and achieve remote code execution, which is typically leveraged for a complete site takeover. Please note that this vulnerability only critically affects users who have enabled the “Public API” option in the settings, which is disabled by default, and have not configured authentication for the API.
Props to ISMAILSHADOW who discovered and responsibly reported this vulnerability through the Wordfence Bug Bounty Program. This vulnerability was disclosed to our program just one day after it was introduced. This researcher earned a bounty of $1,170.00 for this discovery. Our mission is to secure WordPress through defense in depth, which is why we are investing in quality vulnerability research and collaborating with researchers of this caliber through our Bug Bounty Program. We are committed to making the WordPress ecosystem more secure through the detection and prevention of vulnerabilities, which is a critical element to our multi-layered approach to security.
Wordfence Premium, Wordfence Care, and Wordfence Response users received a firewall rule to protect against any exploits targeting this vulnerability on July 21, 2025. Sites using the free version of Wordfence will receive the same protection 30 days later on August 20, 2025.
We provided full disclosure details to Jordy Meow instantly through our Wordfence Vulnerability Management Portal on July 18, 2025. The developer released the patch on July 22, 2025. We would like to commend Jordy Meow for their prompt response and timely patch.
This vulnerability is an incredible example of the positive impact the Wordfence Bug Bounty Program has on the WordPress ecosystem. The vulnerability was introduced on July 17th, 2025, and just one day later was reported to our Bug Bounty Program, triaged, sent to the developer, and patched a few days later, creating a narrow opportunity for attackers to discover and exploit this vulnerability before site owners were protected. Extra special kudos to the researcher ISMAILSHADOW for discovering this vulnerability so quickly and to Jordy Meow for remediating the vulnerability so quickly.
We urge users to update their sites with the latest patched version of AI Engine, version 2.9.5 at the time of this publication, as soon as possible.
Read more in the full blog post: https://www.wordfence.com/blog/2025/0...
Stay informed and secure: read the full details and expert analysis on the Wordfence blog: https://www.wordfence.com/blog/
🔗 Get Wordfence today: https://www.wordfence.com/
🔐 Learn more about WordPress security: https://www.wordfence.com/learn/
🎥 Watch the full WordPress Security Essentials series here:
• WordPress Security Essentials by Wordfence...
Wordfence is designed for defense in depth by giving you a layered approach to security with our range of features.
#WordPress #WordPressSecurity #Cybersecurity #WebsiteProtection #Wordfence #OnlineSecurity #wordpress
===== Protect Your Site With Wordfence =====
✅ Get Wordfence Free: https://www.wordfence.com/products/wo...
✅ Get Wordfence Premium: https://www.wordfence.com/products/wo...
✅ Get Wordfence Care: https://www.wordfence.com/products/wo...
✅ Get Wordfence Response: https://www.wordfence.com/products/wo...
📝 Wordfence Audit Log:
All premium Wordfence plans include access to the Wordfence Audit Log — capturing, securely storing, and protecting important security events for forensic analysis.
🔵 Connect Your Sites To Wordfence Central:
https://www.wordfence.com/help/central/
Manage all your WordPress sites from one centralized dashboard.
💸 Want to earn money promoting Wordfence? Join the Wordfence Affiliate Program:
👉 Learn more: • How To Earn Money With The Wordfence Affil...
👉 Join: https://www.wordfence.com/affiliate
🐞 Earn money via our Bug Bounty Program:
Find vulnerabilities in WordPress plugins and themes and get rewarded!
👉 Join: https://www.wordfence.com/refer/youtube