Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-15982: Aimogen Pro <= 2.8.4: Unauthenticated Admin Account Creation

CVE-2026-15982 CVE-2026-15982
Summary

The Aimogen Pro plugin for WordPress allows unauthorized users to create admin accounts and gain full control of the website. This is a serious security risk because an attacker could use this to take over your site and steal sensitive information. To protect yourself, update the Aimogen Pro plugin to the latest version or remove it if possible.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
coderevolution aimogen pro - all-in-one ai content writer, editor, chatbot & automation toolkit <= 2.8.4
Original title
The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. This is ...
Original description
The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. This is due to due to a missing capability check on the 'aiomatic_call_google_ai_function' function. This makes it possible for unauthenticated attackers to leverage the 'aimogen_wp_god_mode' tool to clear function blacklists and execute arbitrary PHP functions, such as creating administrator accounts.
mitre CVSS3.1 9.8
Vulnerability type
CWE-269 Improper Privilege Management
Published: 17 Jul 2026 · Updated: 20 Jul 2026 · First seen: 17 Jul 2026