Security Advisory

CVE-2026-1359

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-11 07:47:54
Last updated 2026-07-13 14:27:24
Assigner Wordfence
CVSS score 8.8
State PUBLISHED

Description

The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the genolve_setOpt() function in all versions up to, and including, 5.0.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to update arbitrary WordPress options, including enabling user registration and setting the default role to administrator, resulting in privilege escalation.