WordPress · Aimogen Pro · CVE-2026-15982
**Name of the Vulnerable Software and Affected Versions**
Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit versions prior to 2.8.5
**Description**
This issue allows unauthenticated attackers to perform privilege escalation. The flaw exists because the `aiomatic call google ai function()` function lacks a proper capability check. An attacker can exploit this by using the `aimogen wp god mode` tool to clear function blacklists and execute arbitrary PHP functions, which can be used to create administrator accounts.
**Recommendations**
Update to a version newer than 2.8.4.
As a temporary workaround, restrict access to the `aiomatic call google ai function()` function until the update is applied.