Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19924 | The AI Engine plugin for WordPress is vulnerable to open redirect in version 2.8.4. This is due to an insecure OAuth implementation, as the 'redirect_uri' parameter is missing validation during the authorization flow. This makes it possible for unauthenticated attackers to intercept the authorization code and obtain an access token by redirecting the user to an attacker-controlled URI. Note: OAuth is disabled, the 'Meow_MWAI_Labs_OAuth' class is not loaded in the plugin in the patched version 2.8.5. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 13 Aug 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Meowapps
Meowapps ai Engine |
|
| CPEs | cpe:2.3:a:meowapps:ai_engine:2.8.4:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Meowapps
Meowapps ai Engine |
Tue, 08 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Jul 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The AI Engine plugin for WordPress is vulnerable to open redirect in version 2.8.4. This is due to an insecure OAuth implementation, as the 'redirect_uri' parameter is missing validation during the authorization flow. This makes it possible for unauthenticated attackers to intercept the authorization code and obtain an access token by redirecting the user to an attacker-controlled URI. Note: OAuth is disabled, the 'Meow_MWAI_Labs_OAuth' class is not loaded in the plugin in the patched version 2.8.5. | |
| Title | AI Engine 2.8.4 - Insecure OAuth Implementation | |
| Weaknesses | CWE-601 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-07-08T14:28:09.854Z
Reserved: 2025-06-18T13:58:33.637Z
Link: CVE-2025-6238
Updated: 2025-07-08T14:28:04.208Z
Status : Analyzed
Published: 2025-07-04T03:15:22.237
Modified: 2025-08-13T19:34:26.383
Link: CVE-2025-6238
No data.
OpenCVE Enrichment
Updated: 2025-07-13T21:47:34Z
EUVD