PT-2026-60718 · WordPress · Aimogen Pro

·

CVE-2026-15982

·

Published

2026-07-13

·

Updated

2026-07-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit versions prior to 2.8.5
Description This issue allows unauthenticated attackers to perform privilege escalation. The flaw exists because the aiomatic call google ai function() function lacks a proper capability check. An attacker can exploit this by using the aimogen wp god mode tool to clear function blacklists and execute arbitrary PHP functions, which can be used to create administrator accounts.
Recommendations Update to a version newer than 2.8.4. As a temporary workaround, restrict access to the aiomatic call google ai function() function until the update is applied.

Fix

DoS

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15982

Affected Products

Aimogen Pro