WordPress Genemy theme <= 1.6.6 - Broken Access Control vulnerability
Description
Unauthenticated subscribers can access protected functions in Genemy theme <=1.6.6 due to missing authorization checks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Unauthenticated subscribers can access protected functions in Genemy theme <=1.6.6 due to missing authorization checks.
Vulnerability
A broken access control vulnerability exists in the Genemy WordPress theme, affecting versions up to and including 1.6.6. The theme fails to properly authorize or validate nonce tokens in certain functions, allowing unauthenticated or subscriber-level users to execute actions intended for higher-privileged roles [1].
Exploitation
An attacker with subscriber-level access, or even unauthenticated if the WordPress REST API is exposed, can trigger the vulnerable functions without proper authentication. The exact sequence depends on the specific missing check, but generally involves sending a crafted request to a function that should require administrator privileges [1].
Impact
Successful exploitation allows an unprivileged attacker to perform administrative actions, such as altering theme settings, modifying content, or escalating privileges. This can lead to full site compromise, including data disclosure, site defacement, or further injection attacks [1].
Mitigation
Update the Genemy theme to version 1.6.7 or later if available; otherwise, the only workaround is to restrict access to the affected functionality until a patched release is provided. According to the Patchstack advisory, the vulnerability is considered moderately dangerous and likely to be used in mass-exploit campaigns [1].
AI Insight generated on Jun 17, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
1- Wordfence Intelligence Weekly WordPress Vulnerability Report (May 25, 2026 to May 31, 2026)Wordfence Blog · Jun 4, 2026