Executive brief
GetGenie, an AI-powered content and SEO assistant for WordPress, contains a security flaw that allows users with basic 'Subscriber' accounts to access sensitive system information. This exposure could reveal internal data that is normally restricted to administrators, potentially aiding attackers in planning more sophisticated attacks against the website. Business operations may be impacted if sensitive configuration or user data is leaked, leading to further system compromise.
Technical details
The GetGenie plugin for WordPress (versions <= 4.4.2) is vulnerable to an 'Exposure of Sensitive System Information to an Unauthorized Control Sphere' (CWE-497). The vulnerability allows a network-based attacker with low-level 'Subscriber' privileges to bypass intended access controls and view sensitive data. This occurs because the plugin does not sufficiently restrict access to certain internal data points or administrative information. An attacker can exploit this to gather intelligence for further exploitation of the host system. The issue is resolved in version 4.4.3.
Affected products
- Roxnor GetGenie <= 4.4.2
Timeline
- 2026-06-08: other: Reported by Fraudless
- 2026-06-26: disclosed: Published by Patchstack and NVD
- 2026-06-26: patched: Version 4.4.3 released to address the vulnerability