PT-2025-27847 · WordPress · Ai Engine

István Márton

·

Published

2025-07-04

·

Updated

2025-08-13

·

CVE-2025-6238

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: AI Engine plugin for WordPress version 2.8.4
Description: The issue is due to an insecure OAuth implementation, specifically the lack of validation for the redirect uri parameter during the authorization flow. This allows unauthenticated attackers to intercept the authorization code and obtain an access token by redirecting the user to an attacker-controlled URI.
Recommendations: For version 2.8.4, update to version 2.8.5, where OAuth is disabled and the 'Meow MWAI Labs OAuth' class is not loaded, thus mitigating the open redirect vulnerability.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2025-6238

Affected Products

Ai Engine