Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-15982: Aimogen Pro <= 2.8.4: Unauthenticated Admin Account Creation

CVE-2026-15982 · published 2 months ago
Summary

The Aimogen Pro plugin for WordPress allows unauthorized users to create admin accounts and gain full control of the website. This is a serious security risk because an attacker could use this to take over your site and steal sensitive information. To protect yourself, update the Aimogen Pro plugin to the latest version or remove it if possible.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
coderevolution aimogen pro - all-in-one ai content writer, editor, chatbot & automation toolkit <= 2.8.4
Original advisory text
The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. This is ...
The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. This is due to due to a missing capability check on the 'aiomatic_call_google_ai_function' function. This makes it possible for unauthenticated attackers to leverage the 'aimogen_wp_god_mode' tool to clear function blacklists and execute arbitrary PHP functions, such as creating administrator accounts.
Severity
9.8 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-269Improper Privilege Management
Timeline
Published17 Jul 2026
Updated25 Sep 2026
First seen17 Jul 2026
Sources
CVE-2026-15982 · MITRE
Track software like this
Free during beta