{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-07-04T22:45:14.354","vulnerabilities":[{"cve":{"id":"CVE-2025-5071","sourceIdentifier":"security@wordfence.com","published":"2025-06-19T10:15:22.027","lastModified":"2026-06-17T09:47:08.380","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'Meow_MWAI_Labs_MCP::can_access_mcp' function in versions 2.8.0 to 2.8.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to have full access to the MCP and run various commands like 'wp_create_user', 'wp_update_user' and 'wp_update_option', which can be used for privilege escalation, and 'wp_update_post', 'wp_delete_post', 'wp_update_comment' and 'wp_delete_comment', which can be used to edit and delete posts and comments."},{"lang":"es","value":"El complemento AI Engine para WordPress es vulnerable a la modificación no autorizada de datos y a su pérdida debido a la falta de una comprobación de capacidad en la función «Meow_MWAI_Labs_MCP::can_access_mcp» en las versiones 2.8.0 a 2.8.3. Esto permite que atacantes autenticados, con acceso de suscriptor o superior, tengan acceso completo al MCP y ejecuten comandos como «wp_create_user», «wp_update_user» y «wp_update_option», que pueden usarse para la escalada de privilegios, y «wp_update_post», «wp_delete_post», «wp_update_comment» y «wp_delete_comment», que pueden usarse para editar y eliminar publicaciones y comentarios."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"tigroumeow","product":"AI Engine","defaultStatus":"unaffected","versions":[{"version":"2.8.0","lessThanOrEqual":"2.8.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-20T12:49:14.799564Z","id":"CVE-2025-5071","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:meowapps:ai_engine:*:*:*:*:*:wordpress:*:*","versionStartIncluding":"2.8.0","versionEndExcluding":"2.8.4","matchCriteriaId":"55D3B320-631E-44E3-AC72-733028CFFBCC"}]}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/ai-engine/tags/2.8.1/labs/mcp.php#L43","source":"security@wordfence.com","tags":["Product"]},{"url":"https://plugins.trac.wordpress.org/changeset/3313554/ai-engine#file21","source":"security@wordfence.com","tags":["Patch"]},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0e7654a1-0020-4bf1-86be-bdb238a9fe0d?source=cve","source":"security@wordfence.com","tags":["Third Party Advisory"]}]}}]}