CVE-2026-4038: Coderevolution Aimogen Pro - All-In-One Ai Content Writer, Editor, Chatbot & Automation Toolkit
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check on the 'aiomatic_call_ai_function_realtime' function in all versions up to, and including, 2.7.5. This makes it possible for unauthenticated attackers to call arbitrary WordPress functions such as 'update_option' to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
Affected products
- Coderevolution Aimogen Pro - All-In-One Ai Content Writer, Editor, Chatbot & Automation Toolkit: up to and including 2.7.5
Published 2026-03-20. Last modified 2026-06-17.