CyberRota Analysis
AI-GeneratedThe GenieWords WordPress plugin versions 1.5.27 to 1.5.34 lack proper authorization checks on certain REST API and AJAX actions, enabling unauthenticated users to overwrite configurations and inject malicious scripts. This vulnerability poses a significant risk as it allows for the execution of arbitrary web scripts on every front-end page, potentially compromising site integrity and user data. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of exploitation.
Original NVD Description
The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that execute on every front-end page.