Aimogen Pro WordPress Plugin Unauthenticated Privilege Escalation Vulnerability

Vulnerability

A vulnerability in the Aimogen Pro plugin for WordPress, affecting all versions through 2.7.5, allows for unauthenticated privilege escalation. This is due to a missing capability check on the 'aiomatic_call_ai_function_realtime' function, which enables attackers to call arbitrary WordPress functions. Exploitation of this vulnerability could involve using the 'update_option' function to change the default user role for new registrations to administrator, thereby granting administrative access to the attacker.

Impact

Exploitation of this vulnerability could lead to unauthorized administrative access on the affected WordPress site.

Remediation

Users are advised to update the Aimogen Pro plugin to version 2.7.6 or later.

Added: Mar 20, 2026, 4:18 AM
Updated: Mar 20, 2026, 4:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
0.0
relevance
4.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.