Arbitrary Function Call Vulnerability in Aimogen Pro by WordPress
CVE-2026-4038
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 March 2026
What is CVE-2026-4038?
The Aimogen Pro plugin for WordPress is susceptible to an Arbitrary Function Call, which could lead to privilege escalation. This occurs due to a lack of capability checks within the 'aiomatic_call_ai_function_realtime' function. As a result, unauthenticated attackers can exploit this flaw to execute arbitrary WordPress functions, such as 'update_option'. By doing so, they could potentially set the default registration role to administrator, facilitating user registrations that grant administrative access to malicious actors on affected sites. Proper security measures are essential to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit * <= 2.7.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved