كل الثغرات
CWE-295 متوسطة

Improper TLS certificate verification in AI Engine

المورّد Meow Apps
المنتج AI Engine
النسخ المتأثرة < 3.6.5
صنف الضعف CWE-295
تاريخ الإبلاغ 2026-07-28
تاريخ الإفصاح 2026-07-28
الحالة أصلحها المورّد
Discovered and responsibly disclosed a security vulnerability in the AI Engine WordPress plugin, which has 100,000+ active installations. The vulnerability was validated and fixed by the developer in version 3.6.5, with official acknowledgment in the project's changelog. The issue involved improper TLS/SSL certificate verification, which could enable Man-in-the-Middle (MITM) attacks under certain conditions.