Impact
The Genolve AI image and video generation plugin for WordPress is affected by a missing capability check in its genolve_setOpt() function. This flaw allows any authenticated user who has at least Contributor privileges to modify WordPress options arbitrarily. By exploiting this, an attacker can enable site registration or change the default role to Administrator, thereby escalating from a Contributor to a site administrator. The flaw is classified as CWE‑863, an unauthorized modification of data.
Affected Systems
The vulnerability exists in all installations of the Genolve AI plugin for WordPress version 5.0.5 and earlier. The affected product is the Genolve AI Business Graphics, AI Images, and AI Video Generation plugin, maintained by Genolve. No information about protection in later releases is provided in the CVE data.
Risk and Exploitability
The CVSS score of 8.8 places the issue in the high severity range, while the EPSS score below 1 % indicates a very low probability of exploitation at the current time. An attacker must already have authenticated access with Contributor or higher rights; once logged in, the attacker can invoke the vulnerable endpoint to alter critical settings. The flaw is not listed in the CISA KEV catalog, but the combination of high severity and the potential for privilege escalation makes it a critical threat for any WordPress site that continues to run the affected plugin.
OpenCVE Enrichment