PT-2026-3229 · WordPress · Getgenie

Youcef Hamdani

·

Published

2026-01-16

·

Updated

2026-01-16

·

CVE-2026-1003

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GetGenie versions prior to 4.3.1
Description The GetGenie plugin for WordPress has an authorization issue. The plugin does not correctly confirm a user’s permission to delete specific posts. This allows authenticated attackers with Author-level access or higher to delete any post on the WordPress site, even those created by other users.
Recommendations Update GetGenie to version 4.3.1 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-1003

Affected Products

Getgenie