{"api_version":"1","generated_at":"2026-09-14T02:46:06+00:00","cve":"CVE-2026-74933","urls":{"html":"https://cve.report/CVE-2026-74933","api":"https://cve.report/api/cve/CVE-2026-74933.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-74933","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-74933"},"summary":{"title":"GenieWords 1.5.27 - 1.5.34 - Unauthenticated Stored XSS and Configuration Overwrite","description":"The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that execute on every front-end page.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-09-13 21:17:01","updated_at":"2026-09-13 21:17:01"},"problem_types":["CWE-862 Missing Authorization","CWE-79 Cross-Site Scripting (XSS)"],"metrics":[{"version":"3.1","source":"contact@wpscan.com","type":"Secondary","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://wpscan.com/vulnerability/23dc45bb-e7b6-4cae-81ce-2c6394afb454/","name":"https://wpscan.com/vulnerability/23dc45bb-e7b6-4cae-81ce-2c6394afb454/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-74933","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74933","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"GenieWords","version":"affected 1.5.27 1.5.34 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Pablo González Pérez","lang":"en"},{"source":"CNA","value":"Francisco José Ramírez Vicente","lang":"en"},{"source":"CNA","value":"Iñigo Sánchez Enciso","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"collectionURL":"https://wordpress.org/plugins","defaultStatus":"unknown","product":"GenieWords","vendor":"Unknown","versions":[{"lessThanOrEqual":"1.5.34","status":"affected","version":"1.5.27","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Pablo González Pérez"},{"lang":"en","type":"finder","value":"Francisco José Ramírez Vicente"},{"lang":"en","type":"finder","value":"Iñigo Sánchez Enciso"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that execute on every front-end page."}],"metrics":[{"cvssV3_1":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}}],"problemTypes":[{"descriptions":[{"description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}]},{"descriptions":[{"description":"CWE-79 Cross-Site Scripting (XSS)","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-13T20:06:34.552Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/23dc45bb-e7b6-4cae-81ce-2c6394afb454/"}],"source":{"discovery":"EXTERNAL"},"title":"GenieWords 1.5.27 - 1.5.34 - Unauthenticated Stored XSS and Configuration Overwrite","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-74933","datePublished":"2026-09-13T20:06:34.552Z","dateReserved":"2026-08-17T11:38:15.406Z","dateUpdated":"2026-09-13T20:06:34.552Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-13 21:17:01","lastModifiedDate":"2026-09-13 21:17:01","problem_types":["CWE-862 Missing Authorization","CWE-79 Cross-Site Scripting (XSS)"],"metrics":{"cvssMetricV31":[{"source":"contact@wpscan.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"74933","Ordinal":"1","Title":"GenieWords 1.5.27 - 1.5.34 - Unauthenticated Stored XSS and Conf","CVE":"CVE-2026-74933","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"74933","Ordinal":"1","NoteData":"The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that execute on every front-end page.","Type":"Description","Title":"GenieWords 1.5.27 - 1.5.34 - Unauthenticated Stored XSS and Conf"}]}}}