Impact
Unauthenticated users can exploit Insecure Direct Object References in the AI Engine plugin to access or manipulate data they should not see. This flaw enables an attacker to bypass normal authorization checks, potentially reading or modifying sensitive content stored by the plugin. The weakness is identified by CWE‑639 which denotes limitations in authorization controls. Since the plugin accepts identifiers in requests without verifying ownership, a malicious actor can retrieve arbitrary user data or privileged settings.
Affected Systems
The vulnerability affects the WordPress AI Engine plugin by Jordy Meow. Any installation running version 3.7.8 or earlier is impacted. Users should verify the installed version and plan to upgrade to a version newer than 3.7.8.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. There is no EPSS score available, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is a remote web request made by an unauthenticated user, meaning attackers do not need privileged credentials. Given the absence of exploit evidence and the moderate CVSS score, the risk is present but moderate compared to high‑severity flaws. However, any system that relies on strict data isolation may be adversely affected if the IDOR is exploited.
OpenCVE Enrichment