Skip to content
September 29, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Vulnerability Report
  • WordPress AI Engine Flaw (CVE-2025-5071): Critical Bug Allows Subscriber-Level Account Takeover
  • Vulnerability Report

WordPress AI Engine Flaw (CVE-2025-5071): Critical Bug Allows Subscriber-Level Account Takeover

Do Son June 19, 2025 3 minutes read
0
WordPress Privilege Escalation CVE-2026-1492 Sneeit Framework RCE, Unauthenticated Code Execution Post SMTP, Account Takeover WordPress Vulnerability, Unpatched XSS WordPress Vulnerability, PHP Object Injection WordPress AI Engine, Privilege Escalation CVE-2024-43153 & CVE-2024-43234
Add Daily CyberSecurity as a preferred source on Google

Security researchers at Wordfence have uncovered a vulnerability in the popular AI Engine plugin for WordPress, which is installed on more than 100,000 websites. Tracked as CVE-2025-5071, this flaw enables authenticated users with subscriber-level access to escalate their privileges and potentially take full control of a website.

See a WordPress CVE's exploit risk spike before it becomes a headline.

Get EPSS spike alerts →

With a CVSS score of 8.8, the vulnerability affects sites that have Dev Tools and the Model Context Protocol (MCP) module enabled—two features that are disabled by default but may be turned on by site administrators for advanced AI-powered functionality.

AI Engine, developed to integrate AI models like ChatGPT or Claude into WordPress, recently added support for Model Context Protocol (MCP). This protocol empowers AI agents to perform complex administrative tasks, such as managing files, editing users, and controlling site behavior.

While powerful, this feature opens up a dangerous attack surface when misconfigured.

At the core of the issue is the can_access_mcp() function used to validate access to MCP endpoints. The plugin initially grants access to all logged-in users, and allows further control via a filter called ‘mwai_allow_mcp’. Although the plugin offers Bearer Token authentication, the validation logic fails to check for empty values.

“Even when the Bearer Token authentication method is configured… this authentication can be bypassed due to the missing empty value check,” the report explains.

In practice, this means that any logged-in user can access the MCP endpoint if no other checks are implemented—even if the bearer token system is enabled. Once inside, the user can execute the wp_update_user command to promote their account to administrator.

“An attacker… can execute various commands… allowing them to escalate their privileges to administrator,” the report warns.

This kind of privilege escalation results in total site compromise. A user elevated to admin can:

  • Upload malicious plugins or backdoors
  • Modify or delete content
  • Redirect visitors to malicious sites
  • Inject spam or phishing content

While the vulnerability only affects websites with MCP explicitly enabled, the high install base and ease of exploitation make it a significant risk for developers and site owners experimenting with AI automation tools.

Wordfence urges all users of the AI Engine plugin to immediately update to version 2.8.4, which includes a patch for this vulnerability.

Related Posts:

  • AI Dev Gallery: Microsoft Unleashes On-Device AI for Windows 11
  • Google Gemini to Support Anthropic’s Model Context Protocol (MCP)
  • A New Era for Windows: Microsoft’s Protocol Transforms OS into AI Agent Platform
  • Toxic Agent Flow: GitHub MCP Vulnerability Exposes Private Repositories
  • Tool Poisoning Attacks: Critical Vulnerability Discovered in Model Context Protocol (MCP)

Related coverage

  • CVE-2025-4010: ONEKEY Uncovers Critical Remote Code Execution Flaw in Netcomm/Lantronix 4G Gateways
  • 53M Downloads At Risk: Critical 9.8 CVSS Vitest Remote Code Execution Vulnerabilities Disclosed
  • Double Injection Risk in NVIDIA Megatron-LM: Code Execution Flaws Patched in v0.12.1
  • CVE-2025-53786: Microsoft Exchange Hybrid Deployments Expose Cloud Privilege Escalation Risk
  • Chrome 150 Security Update Fixes 15 Flaws, Including Two Critical Use-After-Free Bugs
  • The Events Calendar Vulnerability Exploited in the Wild
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Account Takeover AI AI Engine cybersecurity MCP Model Context Protocol plugin privilege escalation Vulnerability Wordfence wordpress

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 23, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-69431CVSS 9.8
    Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network.
    📅 Updated: Sep 29, 2026
  • CVE-2026-7192CVSS 9.3
    A stack-based buffer overflow vulnerability in the Dbit T-CPE301K 4G WiFi minirouter allows an authenticated attacker to cause...
    📅 Updated: Sep 29, 2026
  • CVE-2026-22094CVSS 9.3
    The firmware for the EVbee DC-80 has a weak hardcoded root password, which allows attackers to login as...
    📅 Updated: Sep 29, 2026
  • CVE-2026-102268CVSS 9.1
    PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected...
    📅 Updated: Sep 29, 2026
  • CVE-2026-100818CVSS 9.6
    Sandbox escape due to use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox ESR 153.4,...
    📅 Updated: Sep 29, 2026
  • CVE-2025-15039CVSS 9.4
    The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when...
    📅 Updated: Sep 29, 2026
  • CVE-2026-6928CVSS 9.8
    IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker...
    📅 Updated: Sep 29, 2026
  • CVE-2026-92035CVSS 9.6
    Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156,...
    📅 Updated: Sep 29, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.