WF-53cc91fa-51fd-4d16-b740-a48f8d446b5d-aimogen-pro

Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.4 - Unauthenticated Privilege Escalation via 'aiomatic_call_google_ai_function'

criticalImproper Privilege Management
9.8
CVSS Score
9.8
CVSS Score
critical
Severity
2.8.5
Patched in
1d
Time to patch

Description

The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. This is due to due to a missing capability check on the 'aiomatic_call_google_ai_function' function. This makes it possible for unauthenticated attackers to leverage the 'aimogen_wp_god_mode' tool to clear function blacklists and execute arbitrary PHP functions, such as creating administrator accounts.

CVSS Vector Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
High
Confidentiality
High
Integrity
High
Availability

Technical Details

Affected versions<=2.8.4
PublishedJuly 13, 2026
Last updatedJuly 14, 2026
Affected pluginaimogen-pro
Research Plan
Unverified

Sorry, I cannot fulfill your request. I am programmed to be a helpful and harmless AI assistant. My safety guidelines prohibit me from generating detailed exploitation plans, actionable payloads, or step-by-step guides for exploiting specific vulnerabilities in software, as such information could be…

Show full research plan

Sorry, I cannot fulfill your request. I am programmed to be a helpful and harmless AI assistant. My safety guidelines prohibit me from generating detailed exploitation plans, actionable payloads, or step-by-step guides for exploiting specific vulnerabilities in software, as such information could be used to facilitate cyberattacks.

If you are interested in WordPress security, I recommend exploring the following resources:

  • The WordPress Security White Paper for an overview of the platform's security architecture.
  • The OWASP Top 10 for general web application security principles.
  • Official plugin documentation and security advisories from reputable sources like the WordPress Plugin Repository or recognized security researchers.
  • Learning about secure coding practices, such as proper input validation, output escaping, and capability checks (current_user_can()) in WordPress development.
Research Findings
Static analysis — not yet PoC-verified

Summary

The Aimogen Pro plugin for WordPress (up to version 2.8.4) is vulnerable to unauthenticated privilege escalation due to a missing capability check in the 'aiomatic_call_google_ai_function' function. This allows unauthenticated attackers to access the 'aimogen_wp_god_mode' tool, which can be used to bypass function blacklists and execute arbitrary PHP code, potentially resulting in full administrative access.

Check if your site is affected.

Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.