← Back to browse · API

CVE-2025-11749

Severity
CRITICAL
CVSS
9.8
EPSS
0.74759
Risk score
65.37
CISA KEV
No
PoC
No
Published
2025-11-05
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2025-37802, GHSA-Q6X7-QQGQ-H832
Products
tigroumeow:AI Engine – The Chatbot, AI Framework & MCP for WordPress 0 ≤3.1.3
Sources
euvd EUVD-2025-37802

Description

The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the /mcp/v1/ REST API endpoint that exposes the 'Bearer Token' value when 'No-Auth URL' is enabled. This makes it possible for unauthenticated attackers to extract the bearer token, which can be used to gain access to a valid session and perform many actions like creating a new administrator account, leading to privilege escalation.

References