CVE-2026-4038Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check on the 'aiomatic_call_ai_function_realtime' function in all versions up to, and including, 2.7.5. This makes it possible for unauthenticated attackers to call arbitrary WordPress functions such as 'update_option' to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 4 mentions (2026-03-20); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-03-20: 4Mentions · 2026-03-21: 1Mentions · 2026-04-01: 1Technical Details · 2026-03-20: 4Technical Details · 2026-03-21: 1Technical Details · 2026-04-01: 103-2003-2104-01
Signal classification1 categories
Disclosure
6100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-204
Disclosure4
2026-03-211
Disclosure1
2026-04-011
Disclosure1
Full discourse6 posts
  • Quttera - eCommerce Security@MNovofastovsky
    Disclosure

    #WordPress Security Alert: CVE-2026-4038 The Aimogen Pro WordPress plugin (up to 2.7.5) contains a critical arbitrary function call flaw that could let unauthenticated attackers change site settings, enable user registration, and gain admin access. Rated 9.8 Critical. Update immediately. #CyberSecurity #WebSecurity #CVE #WebsiteSecurity #Malware #SilentRisk

    Post summary

    The tweet announces a critical flaw in the Aimogen Pro WordPress plugin (up to 2.7.5) that allows unauthenticated attackers to alter settings, enable user registration, and gain admin access, assigning it a 9.8 Critical score and urging users to update immediately.

    0000040
    37 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-4038 - Critical The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check on the 'aiomatic_call_ai_function_real... https://www.thehackerwire.com/vulnerability/CVE-2026-4038/ https://t.co/u2eE3quwyQ

    Post summary

    The post announces a critical vulnerability (CVE‑2026‑4038) in the Aimogen Pro WordPress plugin that allows arbitrary function calls leading to privilege escalation via a missing capability check.

    0000031
    138 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4038 The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check on the 'aiomatic_c… https://www.cve.org/CVERecord?id=CVE-2026-4038

    Post summary

    The Aimogen Pro WordPress plugin suffers from an arbitrary function call vulnerability (CVE-2026-4038) that can lead to privilege escalation due to a missing capability check.

    0000098
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4038 WordPress Aimogen Pro Arbitrary Function Call Vulnerability Enables Privilege Escalation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4038

    Post summary

    The post announces a new CVE (CVE-2026-4038) affecting WordPress Aimogen Pro, describing an arbitrary function call flaw that can lead to privilege escalation.

    0000044
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4038: CRITICAL] WordPress Aimogen Pro plugin up to v2.7.5 is at risk of Arbitrary Function Call exploit affecting users' roles. Unauthenticated attackers could escalate privileges to gain administrat...#cve,CVE-2026-4038,#cybersecurity https://cvefind.com/CVE-2026-4038

    Post summary

    The post announces CVE‑2026‑4038, a critical vulnerability in WordPress Aimogen Pro v2.7.5 that allows arbitrary function calls leading to privilege escalation. No PoC, exploit code, patch, or active exploitation evidence is presented.

    0000046
    604 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-4038: Aimo... Unauthenticated function call to `update_option` = instant admin takeover on 9.8 CVSS WordPress sites running this AI plugin. #WordPressSec #PrivEsc. https://zerodaysignal.com/vulnerability/CVE-2026-4038 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-4038 is publicly disclosed as a high‑severity WordPress admin takeover vulnerability via an unauthenticated `update_option` call; no PoC, exploit tool, or patch information is provided.

    0000055
    155 followersView on X

Explore more