CyberRota Analysis
AI-GeneratedThe AI Engine WordPress plugin prior to version 3.7.2 is vulnerable due to improper handling of caller-supplied URLs, allowing users with subscriber-level accounts to access and exfiltrate arbitrary files from the server. This vulnerability poses a significant risk as it can lead to unauthorized access to sensitive information, particularly in multisite environments where non-super subsite administrators can exploit it. WordPress site administrators and security teams should prioritize patching this vulnerability to protect against potential data breaches.
Original NVD Description
The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local filesystem path before reading the file and forwarding its contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature to be enabled; otherwise the same issue is reachable by an administrator, which on multisite allows a non-super subsite administrator to read the network-shared configuration and its secrets.