216.73.217.22

CVE-2025-6238

· Published 04/07/2025 03:15 · Modified 04/07/2025 03:15

Labels: CVE-2025-6238 2025-07-04CVE-2025-6238CWE-601[email protected]

Essential information

Published
04/07/2025 03:15
Modified
04/07/2025 03:15
Author
Creator
CVSS
8.0 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

The AI Engine plugin for WordPress is vulnerable to open redirect in version 2.8.4. This is due to an insecure OAuth implementation, as the 'redirect_uri' parameter is missing validation during the authorization flow. This makes it possible for unauthenticated attackers to intercept the authorization code and obtain an access token by redirecting the user to an attacker-controlled URI. Note: OAuth is disabled, the 'Meow_MWAI_Labs_OAuth' class is not loaded in the plugin in the patched version 2.8.5.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
wordpress / ai engine cpe:2.3:a:wordpress:ai_engine:2.8.4:*:*:*:*:*:wordpress:*:*

References