{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-29T03:33:07.201","vulnerabilities":[{"cve":{"id":"CVE-2025-7847","sourceIdentifier":"security@wordfence.com","published":"2025-07-31T05:15:26.227","lastModified":"2026-06-17T10:05:46.887","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_simpleFileUpload() function in versions 2.9.3 and 2.9.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server when the REST API is enabled, which may make remote code execution possible."},{"lang":"es","value":"El complemento AI Engine para WordPress es vulnerable a la carga de archivos arbitrarios debido a la falta de validación del tipo de archivo en la función rest_simpleFileUpload() en las versiones 2.9.3 y 2.9.4. Esto permite que atacantes autenticados, con acceso de suscriptor o superior, carguen archivos arbitrarios en el servidor del sitio afectado cuando la API REST está habilitada, lo que puede posibilitar la ejecución remota de código."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"tigroumeow","product":"AI Engine","defaultStatus":"unaffected","versions":[{"version":"2.9.3","lessThanOrEqual":"2.9.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-07-31T13:25:07.791631Z","id":"CVE-2025-7847","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-434"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/ai-engine/tags/2.9.3/classes/api.php#L673","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/ai-engine/tags/2.9.3/classes/modules/files.php#L332","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3329842/ai-engine/trunk/classes/api.php","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3332539%40ai-engine&new=3332539%40ai-engine&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1c1c7ec9-d01f-433d-abec-dc2b6ff684c7?source=cve","source":"security@wordfence.com"}]}}]}