Executive brief
GetGenie, an AI-powered content and SEO assistant plugin for WordPress, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could potentially hijack user sessions, redirect visitors to malicious websites, or deface the site. This vulnerability can be exploited by unauthenticated users, posing a risk to the site's reputation and user data.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the GetGenie WordPress plugin (versions <= 4.4.3) due to improper neutralization of input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary web scripts or HTML. Exploitation requires a victim (typically a site administrator) to perform an action, such as clicking a malicious link or visiting a crafted page (User Interaction required). Successful exploitation can lead to session hijacking, unauthorized actions in the context of the victim's browser, or site defacement. The issue is resolved in version 4.5.0.
Affected products
- Roxnor (Wpmet) GetGenie <= 4.4.3
Timeline
- 2026-07-02: disclosed: Reported by daroo
- 2026-07-27: advisory: Published by Patchstack and NVD
- 2026-07-27: patched: Version 4.5.0 released to address the vulnerability