🔐 CVE Alert

CVE-2026-74933

HIGH 8.8

GenieWords 1.5.27 - 1.5.34 - Unauthenticated Stored XSS and Configuration Overwrite

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that execute on every front-end page.

Vendor unknown
Product geniewords
Published Sep 13, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for unknown geniewords

Be the first to know when new high vulnerabilities affecting unknown geniewords are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Unknown / GenieWords
1.5.27 ≤ 1.5.34

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/23dc45bb-e7b6-4cae-81ce-2c6394afb454/

Credits

Pablo González Pérez Francisco José Ramírez Vicente Iñigo Sánchez Enciso WPScan