Description
The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the genolve_setOpt() function in all versions up to, and including, 5.0.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to update arbitrary WordPress options, including enabling user registration and setting the default role to administrator, resulting in privilege escalation.
Published: 2026-07-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Genolve AI image and video generation plugin for WordPress is affected by a missing capability check in its genolve_setOpt() function. This flaw allows any authenticated user who has at least Contributor privileges to modify WordPress options arbitrarily. By exploiting this, an attacker can enable site registration or change the default role to Administrator, thereby escalating from a Contributor to a site administrator. The flaw is classified as CWE‑863, an unauthorized modification of data.

Affected Systems

The vulnerability exists in all installations of the Genolve AI plugin for WordPress version 5.0.5 and earlier. The affected product is the Genolve AI Business Graphics, AI Images, and AI Video Generation plugin, maintained by Genolve. No information about protection in later releases is provided in the CVE data.

Risk and Exploitability

The CVSS score of 8.8 places the issue in the high severity range, while the EPSS score below 1 % indicates a very low probability of exploitation at the current time. An attacker must already have authenticated access with Contributor or higher rights; once logged in, the attacker can invoke the vulnerable endpoint to alter critical settings. The flaw is not listed in the CISA KEV catalog, but the combination of high severity and the potential for privilege escalation makes it a critical threat for any WordPress site that continues to run the affected plugin.

Generated by OpenCVE AI on July 31, 2026 at 12:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Genolve plugin to a version newer than 5.0.5, if available.
  • If an update is not possible, disable the Genolve plugin or block the genolve_setOpt endpoint from public access.
  • Restrict Contributors so they cannot use the vulnerable endpoint by adjusting role capabilities or removing the relevant capability from the Contributor role.
  • Ensure that user registration is disabled or that the default role is set to a non‑Administrator role to limit potential damage.

Generated by OpenCVE AI on July 31, 2026 at 12:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Genolve
Genolve genolve Ai Business Graphics, Ai Images
Wordpress
Wordpress wordpress
Vendors & Products Genolve
Genolve genolve Ai Business Graphics, Ai Images
Wordpress
Wordpress wordpress

Sat, 11 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the genolve_setOpt() function in all versions up to, and including, 5.0.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to update arbitrary WordPress options, including enabling user registration and setting the default role to administrator, resulting in privilege escalation.
Title Genolve – AI image AI video generation <= 5.0.5 - Authenticated (Contributor+) Incorrect Authorization to Privilege Escalation via theopt
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Genolve Genolve Ai Business Graphics, Ai Images
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-13T14:27:24.334Z

Reserved: 2026-01-22T21:20:10.240Z

Link: CVE-2026-1359

cve-icon Vulnrichment

Updated: 2026-07-13T14:27:19.402Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:45:03Z

Weaknesses