Description
Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through <= 2.8.3.
Published: 2026-07-13
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in CodeRevolution’s Aimogen Pro plugin (CWE-434) allows an attacker to upload files of any type without restriction, including those that could contain executable code. Although the description does not explicitly confirm that the uploaded file will be executed, the reference to \"Using Malicious Files\" implies that a crafted file could be leveraged to compromise the site’s integrity or confidentiality. The flaw provides the potential for remote code execution if an attacker uploads a malicious script that is then executed by the web server.

Affected Systems

All installations of Aimogen Pro version 2.8.3 or earlier are affected. The vulnerability applies from the earliest release of the plugin through version 2.8.3, so any deployment within that range should be considered vulnerable until a patched version is available.

Risk and Exploitability

The CVSS score of 10 illustrates that the flaw is a critical risk. The EPSS score of less than 1% indicates a very low probability of current exploitation, yet the severity remains high. The plugin’s upload interface is typically accessible to users with upload privileges, often administrators or other trusted roles. An attacker who can access that interface can submit a crafted file; since the plugin accepts any MIME type, a malicious PHP or similar script could be placed in a web‑accessible location, enabling remote code execution. The vulnerability is not listed in the CISA KEV catalog, so no confirmed exploit has been reported yet.

Generated by OpenCVE AI on July 31, 2026 at 11:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Aimogen Pro to a version newer than 2.8.3
  • Block or delete non‑safe MIME types and reject uploads that are not explicitly permitted by the plugin’s whitelist
  • If an upgrade cannot be performed immediately, limit the upload capability to trusted administrator accounts only and monitor the upload logs for suspicious activity

Generated by OpenCVE AI on July 31, 2026 at 11:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Coderevolution
Coderevolution aimogen Pro
Wordpress
Wordpress wordpress
Vendors & Products Coderevolution
Coderevolution aimogen Pro
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through <= 2.8.3.
Title WordPress Aimogen Pro plugin <= 2.8.3 - Arbitrary File Upload vulnerability
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Coderevolution Aimogen Pro
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:50.613Z

Reserved: 2026-06-25T08:04:13.263Z

Link: CVE-2026-57719

cve-icon Vulnrichment

Updated: 2026-07-13T16:02:06.261Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:00:05Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type