CVE-2025-7847 is a high-severity arbitrary file upload vulnerability in the AI Engine plugin for WordPress affecting versions 2.9.3 and 2.9.4. The flaw is caused by missing file type validation in the plugin's rest_simpleFileUpload() function exposed through the plugin's REST-based upload functionality. An authenticated attacker with Subscriber-level privileges or higher can upload arbitrary files to the server when the WordPress REST API is enabled. Because the upload handling does not sufficiently restrict dangerous file types or extensions, an attacker may be able to place executable server-side files on the target system. In environments where uploaded executable content can be invoked by the web server, this can result in remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a working exploit for CVE-2025-7847, a vulnerability in the WordPress AI Engine plugin (versions 2.9.3 and 2.9.4) that allows authenticated users to upload arbitrary files via the /wp-json/mwai/v1/simpleFileUpload API endpoint. The exploit is only possible if the plugin's 'Public API' option is enabled and no additional authentication is configured. The repository contains three main Python scripts: - exploit-auto.py: Automates the full attack chain, including login, nonce extraction, file upload, and reverse shell triggering. It can also start a netcat listener for the reverse shell. - exploit-manual.py: Allows file upload using a provided cookie and nonce, for situations where these are already known. - exploit.py: Automates login, nonce extraction, and file upload, but does not trigger a reverse shell. Two PHP payloads are included: - reverse.php: A reverse shell that connects back to the attacker's IP and port. - shell.php: A simple web shell that executes commands provided via the 'cmd' GET parameter. The exploit scripts use the vulnerable API endpoint to upload these payloads, resulting in remote code execution on the target server. The README provides clear usage instructions and highlights the required configuration for successful exploitation. No framework is used; the code is standalone and operational.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An arbitrary file upload vulnerability previously affecting AI Engine versions 2.9.3 and 2.9.4, mentioned only as vendor security history/background.
An authenticated arbitrary file upload vulnerability in the AI Engine WordPress plugin caused by missing file type validation in rest_simpleFileUpload(), affecting versions 2.9.3 and 2.9.4 and potentially enabling remote code execution.
An arbitrary file upload vulnerability in the WordPress AI Engine plugin (versions 2.9.3 and 2.9.4) that can allow an authenticated subscriber-level user to upload executable files and potentially achieve remote code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.