CVE-2025-8268: Tigroumeow Ai Engine – The Chatbot, Ai Framework & Mcp For WordPress

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

The AI Engine plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the rest_list and delete_files functions in all versions up to, and including, 2.9.5. This makes it possible for unauthenticated attackers to list and delete files uploaded by other users.

Affected products

  • Tigroumeow Ai Engine – The Chatbot, Ai Framework & Mcp For WordPress: up to and including 2.9.5

Published 2025-09-03. Last modified 2026-06-17.