logo

CVE-2026-15982: WordPress Aimogen Pro Plugin Privilege Escalation (CVSS 9.8)

ID: c4f5dc35-4e8d-51e5-880f-1fbe6ba49944

STIX ID: report--c4f5dc35-4e8d-51e5-880f-1fbe6ba49944

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-07-17

Date Updated: 2026-07-18

...
...

**CVE-2026-15982 — Aimogen Pro (<= 2.8.4): Critical Privilege Escalation (CVSS 9.8)** — A missing capability check in the aiomatic_call_google_ai_function wp_ajax handler lets any authenticated WordPress user (including Subscriber) trigger a crafted AJAX POST to wp-admin/admin-ajax.php (action=aiomatic_call_google_ai_function) and escalate to Administrator, enabling full site takeover; update to 2.8.5+ or remove the plugin, audit admin accounts, and look for indicators such as unexpected admin accounts, unknown plugins/themes, modified PHP files in wp-content, and POSTs to admin-ajax.php with the vulnerable action.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.