CVE-2026-4038 is a critical arbitrary function call vulnerability (CVSS 9.8) affecting the Aimogen Pro plugin for WordPress, versions up to and including 2.7.5. This flaw stems from a missing capability check, allowing unauthenticated attackers to call arbitrary WordPress functions, such as 'update_option', to elevate their privileges to administrator. The vulnerability has a network attack vector with low complexity, requiring no user interaction or privileges, and can lead to complete compromise of confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code availability, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| CodeRevolution | Aimogen Pro - All-In-One AI Content Writer, Editor, ChatBot & Automation Toolkit | >= 0, <= 2.7.5CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.