1 of 1
Story summary
- Emiliano Versini discovered a critical vulnerability in the AI Engine WordPress plugin (CVE-2025-11749) affecting over 100,000 installations and allowing unauthenticated attackers to gain admin control.
- The flaw lets attackers extract bearer tokens via the REST API, especially with No-Auth URL enabled.
- Version 3.1.4 patches the vulnerability, and administrators should rotate tokens immediately.
- European organizations face rising ransomware, with AI tools enhancing phishing and vishing campaigns.
