PT-2025-27847 · WordPress · Ai Engine
István Márton
·
Published
2025-07-04
·
Updated
2025-08-13
·
CVE-2025-6238
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
AI Engine plugin for WordPress version 2.8.4
Description:
The issue is due to an insecure OAuth implementation, specifically the lack of validation for the
redirect uri parameter during the authorization flow. This allows unauthenticated attackers to intercept the authorization code and obtain an access token by redirecting the user to an attacker-controlled URI.Recommendations:
For version 2.8.4, update to version 2.8.5, where OAuth is disabled and the 'Meow MWAI Labs OAuth' class is not loaded, thus mitigating the open redirect vulnerability.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ai Engine