Drooid Logo
Back to today’s briefing

Story perspectives

Critical AI Plugin Flaw Exposes 100K WordPress Sites

11/6/2025

43 4 Full Breakdown

1 of 1

Story summary
  • Emiliano Versini discovered a critical vulnerability in the AI Engine WordPress plugin (CVE-2025-11749) affecting over 100,000 installations and allowing unauthenticated attackers to gain admin control.
  • The flaw lets attackers extract bearer tokens via the REST API, especially with No-Auth URL enabled.
  • Version 3.1.4 patches the vulnerability, and administrators should rotate tokens immediately.
  • European organizations face rising ransomware, with AI tools enhancing phishing and vishing campaigns.