Description
The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check on the 'aiomatic_call_ai_function_realtime' function in all versions up to, and including, 2.7.5. This makes it possible for unauthenticated attackers to call arbitrary WordPress functions such as 'update_option' to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
INFO
Published Date :
2026-03-20T03:37:02.014Z
Last Modified :
2026-04-08T17:16:49.699Z
Source :
Wordfence
AFFECTED PRODUCTS
The following products are affected by CVE-2026-4038 vulnerability.
| Vendors | Products |
|---|---|
| Coderevolution |
|
| Wordpress |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-4038.