SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-74933

HIGH · CVSS 8.8 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The GenieWords WordPress plugin versions 1.5.27 to 1.5.34 lack proper authorization checks on certain REST API and AJAX actions, enabling unauthenticated users to overwrite configurations and inject malicious scripts. This vulnerability poses a significant risk as it allows for the execution of arbitrary web scripts on every front-end page, potentially compromising site integrity and user data. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-74933
Severity
HIGH
CVSS
8.8
EPSS
0.27%
WordPress

Original NVD Description

The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that execute on every front-end page.