plugin

Aimogen Pro Vulnerabilities

4 known security issues reported for the Aimogen Pro WordPress plugin. Most recent disclosed Jul 13, 2026.

4 critical

Running Aimogen Pro on your site? Check whether your installed version is affected.

Scan your site free

Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.4 - Unauthenticated Privilege Escalation via 'aiomatic_call_google_ai_function'

critical

The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. This is due to due to a missing capability check on the 'aiomatic_call_google_ai_function' function. This makes it possible for una...

CVSS:
9.8
Affected:
up to 2.8.4
Fixed in:
2.8.5
Disclosed:
Jul 13, 2026

CVE-2026-15982 on NVD →

Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.3 - Unauthenticated Arbitrary File Upload

critical

The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 2.8.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affecte...

CVSS:
9.8
Affected:
up to 2.8.3
Fixed in:
2.8.3.1
Disclosed:
Jul 9, 2026

CVE-2026-57719 on NVD →

Aimogen Pro - Unauthenticated Privilege Escalation via Arbitrary Function Call vulnerability

critical

Unauthenticated Privilege Escalation via Arbitrary Function Call vulnerability

CVSS:
9.8
Affected:
up to 2.7.5
Fixed in:
2.7.6
Disclosed:
Mar 20, 2026

Aimogen Pro <= 2.7.5 - Unauthenticated Privilege Escalation via Arbitrary Function Call

critical

The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check on the 'aiomatic_call_ai_function_realtime' function in all versions up to, and including, 2.7.5. This makes it possible for unauthenticated attackers to call arbitrary W...

CVSS:
9.8
Affected:
up to 2.7.5
Fixed in:
2.7.6
Disclosed:
Mar 19, 2026

CVE-2026-4038 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database