Genemy - Creative Minimal Landing Page Builder for Digital Startup Design Studio Agency in Marketing <= 1.6.6 - Authenticated (Subscriber+) Privilege Escalation
high
The Genemy - Creative Minimal Landing Page Builder for Digital Startup Design Studio Agency in Marketing theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their pri...
- CVSS:
- 8.8
- Affected:
- up to 1.6.6
- Fix:
- No patched version reported
- Disclosed:
- May 26, 2026
CVE-2025-69138 on NVD →
Genemy - Creative Minimal Landing Page Builder for Digital Startup Design Studio Agency in Marketing <= 1.6.6 - Missing Authorization
medium
The Genemy - Creative Minimal Landing Page Builder for Digital Startup Design Studio Agency in Marketing theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.6.6. This makes it possible for authenticated attackers, with subscriber-l...
- CVSS:
- 4.3
- Affected:
- up to 1.6.6
- Fix:
- No patched version reported
- Disclosed:
- May 26, 2026
CVE-2025-69137 on NVD →
Genemy <= 1.6.6 - Authenticated (Subscriber+) Server-Side Request Forgery
medium
The Genemy theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query...
- CVSS:
- 6.4
- Affected:
- up to 1.6.6
- Fix:
- No patched version reported
- Disclosed:
- Dec 31, 2025
CVE-2025-59138 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database