Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

CVE-2026-1359: Genolve WordPress Plugin: Unauthorized Data Modification Possible

CVE-2026-1359 CVE-2026-1359
Summary

The Genolve plugin for WordPress allows attackers with Contributor-level access to modify certain settings, potentially enabling user registration and giving attackers administrator privileges. This affects all versions up to 5.0.5. Update the plugin to a secure version to prevent unauthorized modifications.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
genolve genolve – genolve ai business graphics, ai images <= 5.0.5
Original title
The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the genolve_setOpt() function in all versions...
Original description
The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the genolve_setOpt() function in all versions up to, and including, 5.0.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to update arbitrary WordPress options, including enabling user registration and setting the default role to administrator, resulting in privilege escalation.
nvd CVSS3.1 8.8
Vulnerability type
CWE-863 Incorrect Authorization
Published: 11 Jul 2026 · Updated: 20 Jul 2026 · First seen: 11 Jul 2026