CVE-2025-11749 is a critical vulnerability in the AI Engine plugin for WordPress affecting all versions up to and including 3.1.3. When the plugin's MCP functionality is enabled and the 'No-Auth URL' option is turned on, the plugin exposes MCP endpoint details, including a bearer token, through the public WordPress REST API index (/wp-json/). The issue is attributed to improper exposure of sensitive endpoint metadata and insufficient protection of MCP-related REST functionality. An unauthenticated attacker can retrieve the exposed bearer token from the public API index and use it to access the /mcp/v1/ endpoint as an authenticated session. The available content indicates this access can then be used to invoke privileged functionality, including creation of a new administrator account, modification of site settings, and upload of malicious plugins. This creates an attack chain from information disclosure to privilege escalation and ultimately full site compromise, including remote code execution via malicious plugin upload.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (wp_ai_engine_mcp_rce.rb) that exploits an unauthenticated vulnerability (CVE-2025-11749) in the WordPress AI Engine plugin (versions <= 3.1.3). The exploit works by abusing the MCP (Model Context Protocol) REST API endpoint to create a new administrator account without authentication. After gaining admin access, the module uploads a malicious plugin containing a PHP payload, which is then executed to achieve remote code execution (RCE) on the target server. The module supports multiple payload types (PHP, Unix/Linux/Windows command shells) and is weaponized for use within the Metasploit framework. The main attack vector is network-based, targeting exposed WordPress REST API endpoints. The code is well-structured, with clear separation of REST API helpers, user management, and payload execution logic. The only file in the repository is the Metasploit exploit module itself.
This repository contains a Python exploit script (CVE-2025-11749.py) targeting the AI Engine WordPress plugin (versions <= 3.1.3) for an unauthenticated sensitive information exposure vulnerability (CVE-2025-11749). The exploit automates the process of scanning multiple targets (provided in 'list.txt'), extracting sensitive tokens from exposed REST API endpoints, and using those tokens to create new administrator accounts on the affected WordPress sites. The script is multithreaded for efficiency and provides clear output files: 'tokens_only.txt' (extracted tokens), 'success_results.txt' (successful privilege escalations), and 'created_admins.txt' (details of created admin accounts). The repository also includes a README with detailed usage instructions, a license file, and a requirements.txt listing Python dependencies. The exploit is operational, providing a working privilege escalation payload, and is intended for use by security professionals for authorized testing and research.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability in the WordPress AI Engine MCP component, referenced as a Metasploit module PR.
A critical unauthenticated remote code execution vulnerability in the WordPress AI Engine plugin (<= 3.1.3) allows attackers to create administrator accounts and execute arbitrary code if certain MCP options are enabled.
A critical sensitive information exposure and privilege escalation vulnerability in the AI Engine WordPress plugin that exposes an MCP bearer token via the public WordPress REST API index, allowing unauthenticated attackers to gain administrator-level access when the 'No-Auth URL' feature is enabled.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.