Impact
The vulnerability in CodeRevolution’s Aimogen Pro plugin (CWE-434) allows an attacker to upload files of any type without restriction, including those that could contain executable code. Although the description does not explicitly confirm that the uploaded file will be executed, the reference to \"Using Malicious Files\" implies that a crafted file could be leveraged to compromise the site’s integrity or confidentiality. The flaw provides the potential for remote code execution if an attacker uploads a malicious script that is then executed by the web server.
Affected Systems
All installations of Aimogen Pro version 2.8.3 or earlier are affected. The vulnerability applies from the earliest release of the plugin through version 2.8.3, so any deployment within that range should be considered vulnerable until a patched version is available.
Risk and Exploitability
The CVSS score of 10 illustrates that the flaw is a critical risk. The EPSS score of less than 1% indicates a very low probability of current exploitation, yet the severity remains high. The plugin’s upload interface is typically accessible to users with upload privileges, often administrators or other trusted roles. An attacker who can access that interface can submit a crafted file; since the plugin accepts any MIME type, a malicious PHP or similar script could be placed in a web‑accessible location, enabling remote code execution. The vulnerability is not listed in the CISA KEV catalog, so no confirmed exploit has been reported yet.
OpenCVE Enrichment