Junglewise Threat Intelligence

CVE-2026-1359: Genolve WordPress Plugin privilege escalation in genolve_setOpt

CVE-2026-1359 · Severity: high · CVSS 8.8 · Published 2026-07-11

Executive brief

The Genolve plugin for WordPress, which provides AI-driven image and video generation tools, contains a security flaw that allows low-level users to change site settings. An attacker with a basic contributor account could exploit this to grant themselves administrative control over the entire website. This could lead to a complete site takeover, data theft, or the distribution of malicious content.

Technical details

The vulnerability is classified as Incorrect Authorization (CWE-863) within the genolve_setOpt() function. Due to a missing capability check (missing current_user_can() or similar validation), the function allows any authenticated user with at least Contributor-level permissions to modify arbitrary WordPress options in the database. By manipulating these options, an attacker can enable open user registration and set the default user role to 'administrator'. This effectively allows for privilege escalation to full site administrator. The issue affects all versions of the plugin up to and including 5.0.5.

Affected products

  • Genolve Genolve – AI image AI video generation plugin Up to, and including, 5.0.5

Timeline

  • 2026-07-11: disclosed
  • 2026-07-11: advisory

References