The GetGenie plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.3.0. This is due to the plugin not properly verifying that a user is authorized to delete a specific post. This makes it possible for authenticated attackers, with Author-level access and above, to delete any post on the WordPress site, including posts authored by other users.
Metrics
Affected Vendors & Products
References
History
Fri, 16 Jan 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The GetGenie plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.3.0. This is due to the plugin not properly verifying that a user is authorized to delete a specific post. This makes it possible for authenticated attackers, with Author-level access and above, to delete any post on the WordPress site, including posts authored by other users. | |
| Title | GetGenie – AI Content Writer with Keyword Research & SEO Tracking Tools <= 4.3.0 - Missing Authorization to Authenticated (Author+) Arbitrary Post Deletion | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-01-16T07:23:09.127Z
Reserved: 2026-01-15T19:13:12.832Z
Link: CVE-2026-1003
No data.
Status : Received
Published: 2026-01-16T08:15:46.557
Modified: 2026-01-16T08:15:46.557
Link: CVE-2026-1003
No data.
OpenCVE Enrichment
No data.