High severity8.8NVD Advisory· Published Jul 11, 2026· Updated Jul 13, 2026
CVE-2026-1359
CVE-2026-1359
Description
The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the genolve_setOpt() function in all versions up to, and including, 5.0.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to update arbitrary WordPress options, including enabling user registration and setting the default role to administrator, resulting in privilege escalation.
Affected products
1- Range: <=5.0.5
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.