SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-15982

CRITICAL · CVSS 9.8 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Aimogen Pro plugin for WordPress is vulnerable to privilege escalation due to a missing capability check, allowing unauthenticated attackers to exploit the 'aiomatic_call_google_ai_function' to execute arbitrary PHP functions. This can lead to the creation of unauthorized administrator accounts, posing a significant risk to site integrity and security. WordPress site administrators using this plugin should prioritize immediate updates to version 2.8.5 or later to mitigate this critical vulnerability.

CVE
CVE-2026-15982
Severity
CRITICAL
CVSS
9.8
EPSS
0.34%
WordPress

Original NVD Description

The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. This is due to due to a missing capability check on the 'aiomatic_call_google_ai_function' function. This makes it possible for unauthenticated attackers to leverage the 'aimogen_wp_god_mode' tool to clear function blacklists and execute arbitrary PHP functions, such as creating administrator accounts.