Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.8
CVE-2026-1359: Genolve WordPress Plugin: Unauthorized Data Modification Possible
CVE-2026-1359
CVE-2026-1359
Summary
The Genolve plugin for WordPress allows attackers with Contributor-level access to modify certain settings, potentially enabling user registration and giving attackers administrator privileges. This affects all versions up to 5.0.5. Update the plugin to a secure version to prevent unauthorized modifications.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| genolve | genolve – genolve ai business graphics, ai images | <= 5.0.5 |
Original title
The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the genolve_setOpt() function in all versions...
Original description
The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the genolve_setOpt() function in all versions up to, and including, 5.0.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to update arbitrary WordPress options, including enabling user registration and setting the default role to administrator, resulting in privilege escalation.
nvd CVSS3.1
8.8
Vulnerability type
CWE-863
Incorrect Authorization
Published: 11 Jul 2026 · Updated: 20 Jul 2026 · First seen: 11 Jul 2026