PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Misconfiguration·Updated Nov 14, 2025

WordPress AI Engine Plugin - Token Exposure

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-11749
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the /mcp/v1/ REST API endpoint that exposes the 'Bearer Token' value when 'No-Auth URL' is enabled. This makes it possible for unauthenticated attackers to extract the bearer token, which can be used to gain access to a valid session and perform many actions like creating a new administrator account, leading to privilege escalation.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
AI Engine – The Chatbot, AI Framework & MCP for WordPressby tigroumeow
0
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

WordPress AI Engine Plugin - Token Exposure CVE-2025-11749 Scanner | S4E