Impact
The GetGenie plugin does not verify that a user is authorized to delete a specific post. Consequently, any authenticated user with an Author role or higher can delete any post on the WordPress site, regardless of authorship. This privilege escalation can lead to loss of content, defacement, or disruption of the site’s editorial workflow.
Affected Systems
The vulnerability affects the roxnor GetGenie – AI Content Writer with Keyword Research & SEO Tracking Tools plugin for WordPress. All releases up to and including version 4.3.0 are impacted. Users of version 4.3.1 and later are not affected.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score of less than 1% reflects a low likelihood of exploitation, and the flaw is not listed in the CISA KEV catalog. Attackers must already be authenticated with Author or higher privileges and can exploit the vulnerability through the plugin’s API endpoint that handles post deletion. No additional privileges or external vulnerabilities are required beyond those provided by the target user role.
OpenCVE Enrichment