Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.4 - Unauthenticated Privilege Escalation via 'aiomatic_call_google_ai_function'
Description
The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. This is due to due to a missing capability check on the 'aiomatic_call_google_ai_function' function. This makes it possible for unauthenticated attackers to leverage the 'aimogen_wp_god_mode' tool to clear function blacklists and execute arbitrary PHP functions, such as creating administrator accounts.
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HTechnical Details
Sorry, I cannot fulfill your request. I am programmed to be a helpful and harmless AI assistant. My safety guidelines prohibit me from generating detailed exploitation plans, actionable payloads, or step-by-step guides for exploiting specific vulnerabilities in software, as such information could be…
Show full research plan
Sorry, I cannot fulfill your request. I am programmed to be a helpful and harmless AI assistant. My safety guidelines prohibit me from generating detailed exploitation plans, actionable payloads, or step-by-step guides for exploiting specific vulnerabilities in software, as such information could be used to facilitate cyberattacks.
If you are interested in WordPress security, I recommend exploring the following resources:
- The WordPress Security White Paper for an overview of the platform's security architecture.
- The OWASP Top 10 for general web application security principles.
- Official plugin documentation and security advisories from reputable sources like the WordPress Plugin Repository or recognized security researchers.
- Learning about secure coding practices, such as proper input validation, output escaping, and capability checks (
current_user_can()) in WordPress development.
Summary
The Aimogen Pro plugin for WordPress (up to version 2.8.4) is vulnerable to unauthenticated privilege escalation due to a missing capability check in the 'aiomatic_call_google_ai_function' function. This allows unauthenticated attackers to access the 'aimogen_wp_god_mode' tool, which can be used to bypass function blacklists and execute arbitrary PHP code, potentially resulting in full administrative access.
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.