Impact
The AI Engine WordPress plugin does not sanitize user‑supplied filenames before writing downloaded content, permitting an attacker with editor‑level access to specify a file path that uses directory‑traversal characters. This flaw allows the attacker to create or overwrite any file within the server’s filesystem hierarchy, potentially deploying malicious code, tampering with configuration files, or otherwise compromising the integrity and availability of the site. The vulnerability enables modification of sensitive files, leading to unauthorized code execution and data loss.
Affected Systems
Vulnerable installations of the AI Engine WordPress plugin with versions older than 3.5.5 are at risk. All servers hosting the plugin and granting editor‑level permissions to authenticated users must be checked. The vendor is listed simply as "AI Engine"; no further vendor details are available.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score of less than 1% suggests a low probability of real‑world exploitation at present, but the impact remains significant. Exploitation requires only authenticated access with editor or higher privileges, a common role for content creators. An attacker can trigger the flaw by uploading or downloading a file via the plugin’s interface with a crafted filename that includes traversal sequences, resulting in an unintended write to an arbitrary location on the server. Once exploited, the attacker effectively gains control over critical files or can plant malicious payloads.
OpenCVE Enrichment