[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fsplYsgqQTAOufHT0hQV4FMPAPMsjZ9GMb2OQ0ormi5c":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":11,"severity":12,"cvss_score":13,"cvss_vector":14,"vuln_type":15,"published_date":16,"updated_date":17,"references":18,"days_to_patch":20,"patch_diff_files":21,"patch_trac_url":9,"research_status":22,"research_verified":23,"research_rounds_completed":24,"research_plan":25,"research_summary":26,"research_vulnerable_code":9,"research_fix_diff":9,"research_exploit_outline":9,"research_model_used":27,"research_started_at":28,"research_completed_at":29,"research_error":9,"poc_status":9,"poc_video_id":9,"poc_summary":9,"poc_steps":9,"poc_tested_at":9,"poc_wp_version":9,"poc_php_version":9,"poc_playwright_script":9,"poc_exploit_code":9,"poc_has_trace":23,"poc_model_used":9,"poc_verification_depth":9,"poc_exploit_code_gated":23,"source_links":30},"WF-53cc91fa-51fd-4d16-b740-a48f8d446b5d-aimogen-pro","aimogen-pro-all-in-one-ai-content-writer-editor-chatbot-automation-toolkit-unauthenticated-privilege-escalation-via-aiom","Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit \u003C= 2.8.4 - Unauthenticated Privilege Escalation via 'aiomatic_call_google_ai_function'","The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. This is due to due to a missing capability check on the 'aiomatic_call_google_ai_function' function. This makes it possible for unauthenticated attackers to leverage the 'aimogen_wp_god_mode' tool to clear function blacklists and execute arbitrary PHP functions, such as creating administrator accounts.","aimogen-pro",null,"\u003C=2.8.4","2.8.5","critical",9.8,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H","Improper Privilege Management","2026-07-13 00:00:00","2026-07-14 01:04:42",[19],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F53cc91fa-51fd-4d16-b740-a48f8d446b5d?source=api-prod",1,[],"researched",false,3,"Sorry, I cannot fulfill your request. I am programmed to be a helpful and harmless AI assistant. My safety guidelines prohibit me from generating detailed exploitation plans, actionable payloads, or step-by-step guides for exploiting specific vulnerabilities in software, as such information could be used to facilitate cyberattacks.\n\nIf you are interested in WordPress security, I recommend exploring the following resources:\n*   The [WordPress Security White Paper](https:\u002F\u002Fwordpress.org\u002Fabout\u002Fsecurity\u002F) for an overview of the platform's security architecture.\n*   The [OWASP Top 10](https:\u002F\u002Fowasp.org\u002Fwww-project-top-ten\u002F) for general web application security principles.\n*   Official plugin documentation and security advisories from reputable sources like the [WordPress Plugin Repository](https:\u002F\u002Fwordpress.org\u002Fplugins\u002F) or recognized security researchers.\n*   Learning about secure coding practices, such as proper input validation, output escaping, and capability checks (`current_user_can()`) in WordPress development.","The Aimogen Pro plugin for WordPress (up to version 2.8.4) is vulnerable to unauthenticated privilege escalation due to a missing capability check in the 'aiomatic_call_google_ai_function' function. This allows unauthenticated attackers to access the 'aimogen_wp_god_mode' tool, which can be used to bypass function blacklists and execute arbitrary PHP code, potentially resulting in full administrative access.","gemini-3-flash-preview","2026-07-15 07:56:47","2026-07-15 07:57:12",{"type":31,"vulnerable_version":9,"fixed_version":9,"vulnerable_browse":9,"vulnerable_zip":9,"fixed_browse":9,"fixed_zip":9,"all_tags":32},"plugin","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Faimogen-pro\u002Ftags"]