CVE-2026-57719
Deferred Deferred - Pending Action

Unrestricted File Upload in Aimogen Pro

Vulnerability report for CVE-2026-57719, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-13

Last updated on: 2026-07-13

Assigner: Patchstack

Description

Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through <= 2.8.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-13
Last Modified
2026-07-13
Generated
2026-08-02
AI Q&A
2026-07-13
EPSS Evaluated
2026-08-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
coderevolution aimogen_pro to 2.8.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in the WordPress Aimogen Pro Plugin (version 2.8.3 and below) is an Arbitrary File Upload issue. It allows unauthenticated attackers to upload any type of file, including dangerous or malicious files such as backdoors, to the affected website.

Detection Guidance

This vulnerability allows unauthenticated attackers to upload arbitrary files, including malicious backdoors, to the website. Detection can involve monitoring for unusual file uploads or unexpected files in the Aimogen Pro plugin directories.

Specific commands are not provided in the available resources, but common approaches include checking web server upload directories for suspicious files and reviewing web server logs for unusual POST requests targeting the Aimogen Pro plugin upload endpoints.

Impact Analysis

This vulnerability can lead to a complete compromise of the affected website. Attackers can upload malicious files that may allow them to execute arbitrary code, gain unauthorized access, manipulate data, or disrupt the availability of the site.

Compliance Impact

This vulnerability can significantly impact compliance with standards and regulations like GDPR and HIPAA due to its severe security implications.

  • GDPR: The unrestricted file upload vulnerability allows attackers to upload malicious files, potentially leading to unauthorized access to sensitive personal data. Under GDPR, organizations must protect personal data from breaches. A successful exploit could result in a data breach, triggering mandatory reporting requirements and potential fines for non-compliance with data protection obligations.
  • HIPAA: For organizations handling protected health information (PHI), this vulnerability poses a risk of unauthorized access or disclosure of PHI. HIPAA requires safeguards to ensure the confidentiality, integrity, and availability of PHI. A breach resulting from this vulnerability could lead to violations of the HIPAA Security Rule, resulting in penalties and corrective action plans.

Additionally, the high CVSS score (10.0) indicates a critical risk, which may require immediate remediation to meet compliance requirements for security controls and risk management under frameworks like ISO 27001 or NIST.

Mitigation Strategies

Immediate mitigation steps include updating the Aimogen Pro plugin to version 2.8.3.1 or later, which contains the patch for this vulnerability.

Until the plugin is updated, applying the Patchstack mitigation rule to block attacks targeting this vulnerability is advised.

Additionally, seeking assistance from your hosting provider or a developer to implement temporary protections or monitoring is recommended.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57719. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart