Executive brief
GetGenie, an AI-powered content and SEO plugin for WordPress, contains a security flaw that allows unauthorized individuals to access sensitive information. This could lead to the exposure of data that is normally restricted to authorized users, potentially providing attackers with information needed to launch further attacks against the website. Business operations may be impacted if confidential configuration or user data is leaked.
Technical details
The GetGenie plugin for WordPress (versions <= 4.4.1) is vulnerable to an unauthenticated sensitive data exposure flaw, classified as CWE-201 (Insertion of Sensitive Information Into Sent Data). The vulnerability allows a remote attacker to access sensitive information without any prior authentication or user interaction. This occurs because the plugin fails to properly restrict access to certain data outputs or logs. Attackers can leverage this exposed information to gain insights into the system's configuration or user details, which can facilitate more complex subsequent attacks. A patch is available in version 4.4.2.
Affected products
- Wpmet GetGenie <= 4.4.1
Timeline
- 2026-04-21: other: Vulnerability reported by researcher hhhai
- 2026-06-15: advisory: Patchstack advisory published
- 2026-06-16: disclosed: CVE published to NVD dataset
- 2026-06-15: patched: Version 4.4.2 released to address the issue