Description

The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check on the 'aiomatic_call_ai_function_realtime' function in all versions up to, and including, 2.7.5. This makes it possible for unauthenticated attackers to call arbitrary WordPress functions such as 'update_option' to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

INFO

Published Date :

2026-03-20T03:37:02.014Z

Last Modified :

2026-04-08T17:16:49.699Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2026-4038 vulnerability.

Vendors Products
Coderevolution
  • Aimogen Pro - All-in-one Ai Content Writer, Editor, Chatbot & Automation Toolkit
Wordpress
  • Wordpress

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact