CVE-2026-74933
GenieWords 1.5.27 - 1.5.34 - Unauthenticated Stored XSS and Configuration Overwrite
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that execute on every front-end page.
| Vendor | unknown |
| Product | geniewords |
| Published | Sep 13, 2026 |
| Last Updated | Sep 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown geniewords
Be the first to know when new high vulnerabilities affecting unknown geniewords are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Unknown / GenieWords
1.5.27 ≤ 1.5.34
References
Credits
Pablo González Pérez Francisco José Ramírez Vicente Iñigo Sánchez Enciso WPScan