Executive brief
CodeRevolution Aimogen Pro, a WordPress plugin, contains a critical security flaw that allows unauthorized users to upload malicious files to a website. An attacker can use this to install backdoors, take full control of the site, or steal sensitive data. This vulnerability is highly dangerous as it requires no login credentials and can be exploited remotely.
Technical details
The CodeRevolution Aimogen Pro plugin (versions up to and including 2.8.3) suffers from an Unrestricted Upload of File with Dangerous Type vulnerability (CWE-434). The flaw allows an unauthenticated remote attacker to upload arbitrary files, such as PHP scripts, to the server. Because the plugin fails to properly validate file extensions or content, these files can be executed to achieve full Remote Code Execution (RCE). The vulnerability has been addressed in version 2.8.3.1.
Affected products
- CodeRevolution Aimogen Pro <= 2.8.3
Timeline
- 2026-06-30: disclosed: Reported by 0xd4rk5id3
- 2026-07-09: advisory: Patchstack published advisory
- 2026-07-13: advisory: NVD published CVE record
- 2026-07-13: patched: Version 2.8.3.1 released to address the issue