كل الثغرات
CWE-295
متوسطة
Improper TLS certificate verification in AI Engine
| المورّد | Meow Apps |
|---|---|
| المنتج | AI Engine |
| النسخ المتأثرة | < 3.6.5 |
| صنف الضعف | CWE-295 |
| تاريخ الإبلاغ | 2026-07-28 |
| تاريخ الإفصاح | 2026-07-28 |
| الحالة | أصلحها المورّد |
Discovered and responsibly disclosed a security vulnerability in the AI Engine WordPress plugin, which has 100,000+ active installations. The vulnerability was validated and fixed by the developer in version 3.6.5, with official acknowledgment in the project's changelog. The issue involved improper TLS/SSL certificate verification, which could enable Man-in-the-Middle (MITM) attacks under certain conditions.