PT-2026-60718 · WordPress · Aimogen Pro
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit versions prior to 2.8.5
Description
This issue allows unauthenticated attackers to perform privilege escalation. The flaw exists because the
aiomatic call google ai function() function lacks a proper capability check. An attacker can exploit this by using the aimogen wp god mode tool to clear function blacklists and execute arbitrary PHP functions, which can be used to create administrator accounts.Recommendations
Update to a version newer than 2.8.4.
As a temporary workaround, restrict access to the
aiomatic call google ai function() function until the update is applied.Fix
DoS
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aimogen Pro