CVE-2026-1359
genolve Genolve – Genolve AI Business Graphics, AI Images
The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the genolve_setOpt() function in all versions up to, and including, 5.0.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to update arbitrary WordPress options, including enabling user registration and setting the default role to administrator, resulting in privilege escalation.
- CVSS
- 8.8
- EPSS
- 0.30% 22.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.11