The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that execute on every front-end page.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that execute on every front-end page. | |
| Title | GenieWords 1.5.27 - 1.5.34 - Unauthenticated Stored XSS and Configuration Overwrite | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-13T20:06:34.552Z
Reserved: 2026-08-17T11:38:15.406Z
Link: CVE-2026-74933
No data.
Status : Received
Published: 2026-09-13T21:17:01.800
Modified: 2026-09-13T21:17:01.800
Link: CVE-2026-74933
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.