WordPress security by component
GetGenie
Plugin description
GetGenie is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 7.1.
Plugin slug:
getgenieLatest vulnerability
CVE-2026-65440: GetGenie public input permits cross-site scripting
GetGenie through 4.4.3 accepts attacker-controlled input through an unauthenticated request path and places it into a browser-executable output context without adequate neutralization. A victim who opens the crafted output can run script in the site's origin. The Patchstack CNA record does not disclose whether the payload is reflected or stored, or identify the endpoint, action, parameter or rendering function.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-65440
GetGenie public input permits cross-site scripting
GetGenie through 4.4.3 accepts attacker-controlled input through an unauthenticated request path and places it into a browser-executable output context without adequate neutralization. A victim who opens the crafted output can run script in the site's origin. The Patchstack CNA record does not disclose whether the payload is reflected or stored, or identify the endpoint, action, parameter or rendering function.
|
4.5.0 |
CVE7.1
NVDPending
|
| Jun 26, 2026 |
CVE-2026-57316
GetGenie: A security weakness
GetGenie is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.4.2.
|
4.4.3 |
CVE6.5
NVDPending
|
| Jun 16, 2026 |
CVE-2026-54197
GetGenie: A security weakness
GetGenie is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.4.1.
|
4.4.2 |
CVE6.5
NVDPending
|
| Mar 13, 2026 |
CVE-2026-2879
GetGenie: A security weakness
GetGenie is affected by a security weakness. Exploitation requires at least author-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Mar 13, 2026 |
CVE-2026-2257
GetGenie: Cross-site scripting
GetGenie is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jan 22, 2026 |
CVE-2026-24356
GetGenie: A security weakness
GetGenie is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.9
NVDPending
|
| Jan 16, 2026 |
CVE-2026-1003
GetGenie: A security weakness
GetGenie is affected by a security weakness. Exploitation requires at least author-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|