{
    "id": "CVE-2025-11749",
    "published": "2025-11-05 06:15:33",
    "last_modified": "2026-06-17 08:31:06",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-200",
    "description": "The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the /mcp/v1/ REST API endpoint that exposes the 'Bearer Token' value when 'No-Auth URL' is enabled. This makes it possible for unauthenticated attackers to extract the bearer token, which can be used to gain access to a valid session and perform many actions like creating a new administrator account, leading to privilege escalation.",
    "epss_score": "0.74759",
    "epss_percentile": "0.99491",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-09-29 18:17:44",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "EPSS 74.8% — above the 10% action threshold."
    },
    "products": [],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "https://plugins.trac.wordpress.org/browser/ai-engine/trunk/labs/mcp.php#L226",
        "https://plugins.trac.wordpress.org/changeset/3380753/ai-engine#file10",
        "https://www.wordfence.com/threat-intel/vulnerabilities/id/06eaf624-aedf-453d-8457-d03a572fac0d?source=cve"
    ]
}