Quttera - eCommerce Security[verified]@MNovofastovskyDisclosure
The tweet announces a critical flaw in the Aimogen Pro WordPress plugin (up to 2.7.5) that allows unauthenticated attackers to alter settings, enable user registration, and gain admin access, assigning it a 9.8 Critical score and urging users to update immediately.
The Hacker Wire@TheHackerWireDisclosure
The post announces a critical vulnerability (CVE‑2026‑4038) in the Aimogen Pro WordPress plugin that allows arbitrary function calls leading to privilege escalation via a missing capability check.
CVE@CVEnewDisclosure
The Aimogen Pro WordPress plugin suffers from an arbitrary function call vulnerability (CVE-2026-4038) that can lead to privilege escalation due to a missing capability check.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The post announces a new CVE (CVE-2026-4038) affecting WordPress Aimogen Pro, describing an arbitrary function call flaw that can lead to privilege escalation.
CVEFind.com@CveFindComDisclosure
The post announces CVE‑2026‑4038, a critical vulnerability in WordPress Aimogen Pro v2.7.5 that allows arbitrary function calls leading to privilege escalation. No PoC, exploit code, patch, or active exploitation evidence is presented.
0day Signal@0dayPublishingDisclosure
CVE-2026-4038 is publicly disclosed as a high‑severity WordPress admin takeover vulnerability via an unauthenticated `update_option` call; no PoC, exploit tool, or patch information is provided.