Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-15982: Aimogen Pro <= 2.8.4: Unauthenticated Admin Account Creation
CVE-2026-15982
CVE-2026-15982
Summary
The Aimogen Pro plugin for WordPress allows unauthorized users to create admin accounts and gain full control of the website. This is a serious security risk because an attacker could use this to take over your site and steal sensitive information. To protect yourself, update the Aimogen Pro plugin to the latest version or remove it if possible.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| coderevolution | aimogen pro - all-in-one ai content writer, editor, chatbot & automation toolkit | <= 2.8.4 |
Original title
The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. This is ...
Original description
The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. This is due to due to a missing capability check on the 'aiomatic_call_google_ai_function' function. This makes it possible for unauthenticated attackers to leverage the 'aimogen_wp_god_mode' tool to clear function blacklists and execute arbitrary PHP functions, such as creating administrator accounts.
mitre CVSS3.1
9.8
Vulnerability type
CWE-269
Improper Privilege Management
Published: 17 Jul 2026 · Updated: 20 Jul 2026 · First seen: 17 Jul 2026