"Flaw in AI Plugin Exposes 50,000 WordPress Sites to Remote Attack"
"Flaw in AI Plugin Exposes 50,000 WordPress Sites to Remote Attack"
Security researchers at Patchstack discovered a critical vulnerability in the AI Engine plugin for WordPress, specifically affecting its free version with over 50,000 active installations. The plugin is widely recognized for its diverse AI-related functionalities, allowing users to create chatbots, manage content, and utilize various AI tools such as translation, SEO, and more. The researchers noted that the security flaw is an unauthenticated arbitrary file upload vulnerability in the plugin’s rest_upload function within the files.php module.