Junglewise Threat Intelligence

CVE-2026-15982: CodeRevolution Aimogen Pro privilege escalation in aiomatic_call_google_ai_function

CVE-2026-15982 · Severity: critical · CVSS 9.8 · Published 2026-07-17

Executive brief

The Aimogen Pro plugin for WordPress, which provides AI-driven content creation and chatbot tools, contains a critical security flaw. This vulnerability allows an unauthorized person to bypass security checks and execute administrative commands on the website. An attacker could use this to take full control of the site, including creating new administrator accounts or deleting data.

Technical details

The Aimogen Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to and including 2.8.4. The flaw exists due to a missing capability check on the 'aiomatic_call_google_ai_function' function. This oversight allows unauthenticated attackers to utilize the 'aimogen_wp_god_mode' tool to bypass function blacklists. Consequently, an attacker can execute arbitrary PHP functions, which can be leveraged to create unauthorized administrator accounts or achieve full remote code execution on the affected WordPress instance.

Affected products

  • CodeRevolution Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit up to, and including, 2.8.4

Timeline

  • 2026-07-17: advisory: Advisory published by Wordfence and NVD

References