CVE-2025-8084 Overview
The AI Engine plugin for WordPress contains a Server-Side Request Forgery (SSRF) vulnerability in the rest_helpers_create_images function. The flaw affects all versions up to and including 3.1.8. Authenticated attackers with Editor-level access or above can force the web application to issue arbitrary outbound HTTP requests. This exposure enables interaction with internal services that are otherwise unreachable from the public internet. On cloud-hosted instances, attackers can query provider metadata endpoints and retrieve sensitive instance information. The vulnerability is classified under CWE-918: Server-Side Request Forgery.
Critical Impact
Authenticated Editor-level users can pivot into internal networks and, on AWS, Azure, or GCP instances, retrieve cloud metadata that may include IAM credentials.
Affected Products
- AI Engine plugin for WordPress — all versions up to and including 3.1.8
- WordPress sites running the vulnerable plugin with Editor-level users provisioned
- Cloud-hosted WordPress deployments exposing instance metadata services (IMDS)
Discovery Timeline
- 2025-11-18 - CVE-2025-8084 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-8084
Vulnerability Analysis
The AI Engine plugin exposes REST endpoints that accept user-supplied URLs and fetch remote resources server-side. The rest_helpers_create_images function processes image generation requests and issues outbound HTTP calls to the URLs it receives. The function does not restrict the destination host, port, or scheme before performing the request.
An Editor-level authenticated user can supply a URL pointing to internal infrastructure. The WordPress server then acts as an unwilling proxy, returning or acting on the response. This turns the WordPress host into a launch point for internal reconnaissance and service interaction. The attack primarily impacts confidentiality by disclosing responses from internal endpoints.
Root Cause
The root cause is missing validation of the destination URL prior to invoking the HTTP client. The plugin trusts input passed to the image-creation helper without enforcing an allowlist of external image hosts. It also does not block requests to private IP ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), loopback addresses, or link-local addresses such as 169.254.169.254. See the WordPress AI Engine REST class source and the image service source for the affected code paths.
Attack Vector
The attack requires an authenticated session with Editor privileges or higher. The attacker submits a crafted request to the plugin's REST endpoint, specifying an internal or cloud metadata URL as the image source. The WordPress server issues the outbound request and returns the response body or reflects it through side channels.
On AWS instances that permit IMDSv1, an attacker can request http://169.254.169.254/latest/meta-data/iam/security-credentials/ to retrieve temporary IAM credentials. Similar metadata endpoints exist on Azure (169.254.169.254/metadata/instance) and GCP (metadata.google.internal). See the Wordfence vulnerability analysis for additional technical context.
Detection Methods for CVE-2025-8084
Indicators of Compromise
- Outbound HTTP requests from the WordPress PHP worker process to private IP ranges or 169.254.169.254
- Web server access logs showing authenticated POST or PUT requests to AI Engine REST routes referencing non-image internal URLs
- Unexpected access attempts against internal admin panels, databases, or metadata services originating from the WordPress host IP
- New or unusual IAM credential usage from tokens tied to the WordPress instance role
Detection Strategies
- Inspect PHP-FPM or web server egress traffic for connections to RFC1918 and link-local destinations that do not match legitimate integrations
- Correlate AI Engine REST endpoint access with the User-Agent and source IP of the invoking Editor account
- Alert on any HTTP request from WordPress hosts to 169.254.169.254, metadata.google.internal, or the Azure IMDS path
Monitoring Recommendations
- Enable VPC flow logs on cloud-hosted WordPress workloads and forward them to a centralized analytics pipeline
- Audit AI Engine plugin usage and Editor-tier account activity for unusual REST call patterns
- Monitor CloudTrail, Azure Activity Logs, or GCP Audit Logs for API calls made with the instance role from unexpected contexts
How to Mitigate CVE-2025-8084
Immediate Actions Required
- Update the AI Engine plugin to a version later than 3.1.8 that addresses the SSRF condition
- Audit all WordPress accounts with Editor role or higher and revoke privileges from unnecessary users
- Enforce IMDSv2 on AWS EC2 instances hosting WordPress to require session tokens for metadata access
- Rotate any IAM credentials, API keys, or secrets accessible from the WordPress host if compromise is suspected
Patch Information
Upgrade the AI Engine plugin to a fixed release beyond 3.1.8. Consult the Wordfence vulnerability record for the specific patched version and the plugin changelog on the WordPress plugin directory.
Workarounds
- Temporarily deactivate the AI Engine plugin until the patched version is deployed
- Restrict egress from WordPress hosts to only required external services using a firewall or cloud security group
- Block outbound traffic to 169.254.169.254 and RFC1918 ranges from the WordPress workload where feasible
- Downgrade or remove Editor-level privileges from users who do not require them
# Example AWS CLI command to require IMDSv2 on an EC2 instance
aws ec2 modify-instance-metadata-options \
--instance-id i-0123456789abcdef0 \
--http-tokens required \
--http-endpoint enabled
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
