---
id: CVE-2026-74933
title: >-
  The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have
  authorisation checks on some of its REST API and AJAX actions, and decodes
  stored values before printing them, allowing unauthenticated users to
  overwrite its configurat…
summary: >-
  The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have
  authorisation checks on some of its REST API and AJAX actions, and decodes
  stored values before printing them, allowing unauthenticated users to
  overwrite its configurat…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-862
  - CWE-79
product: GenieWords
affected:
  - GenieWords >= 1.5.27 <= 1.5.34
published: '2026-09-13'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T21:10:17.423'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-74933'
references:
  - url: 'https://wpscan.com/vulnerability/23dc45bb-e7b6-4cae-81ce-2c6394afb454/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-14T12:38:06.421335Z'
ingestedAt: '2026-09-14T15:23:07.431Z'
epss: 0.00502
epssPercentile: 0.40289
---

## Overview

The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that execute on every front-end page.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
