PT-2026-26553 · WordPress · Aimogen Pro

Hung Nguyen

·

Publicado

2026-03-20

·

Atualizado

2026-04-01

·

CVE-2026-4038

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Aimogen Pro versions up to 2.7.5
Description The Aimogen Pro plugin for WordPress is susceptible to an Arbitrary Function Call, potentially leading to privilege escalation. This is due to a missing capability check within the aiomatic call ai function realtime function. Unauthenticated attackers can exploit this to invoke arbitrary WordPress functions, such as update option, to modify site settings. Specifically, attackers can update the default user role for registration to administrator, enabling them to gain administrative access to a vulnerable site. The update option function allows modification of WordPress options, potentially impacting site security and functionality.
Recommendations Aimogen Pro versions prior to 2.7.5 should be updated. As a temporary workaround, consider disabling the aiomatic call ai function realtime function until a patch is available.

Correção

LPE

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-4038

Produtos afetados

Aimogen Pro