Impact
The GenieWords WordPress plugin, from versions 1.5.27 through 1.5.34, contains REST API and AJAX actions that lack proper authorization checks. When user‑supplied data is stored, it is decoded before being rendered on public pages, allowing an unauthenticated user to overwrite configuration values and inject arbitrary JavaScript. This stored XSS can run in the browsers of any visitor to the site, potentially leading to defacement, phishing, session hijacking, or other client‑side attacks.
Affected Systems
All WordPress installations that have the GenieWords plugin installed between versions 1.5.27 and 1.5.34 are affected. The vulnerability applies to the exposed options for management of the plugin’s settings.
Risk and Exploitability
The reflecting the combined impact of privilege escalation (unrestricted write access) and client‑side attack vectors. The EPSS score of < 1% indicates a very low current exploitation probability, yet the lack of authentication requirements and direct HTTP API entry points suggest that exploitation is straightforward and only requires a user‑oriented HTTP request to the plugin. The vulnerability is not currently listed in the CISA KEV catalog, but its high impact and low barrier to exploitation make it a priority for remediation.
OpenCVE Enrichment