CyberRota Analysis
AI-GeneratedThe Geeky Bot WordPress plugin prior to version 1.2.8 is vulnerable due to a lack of authorization checks on specific AJAX actions, enabling unauthenticated users to access sensitive chat-history session metadata, including WordPress usernames and user IDs. This exposure can lead to unauthorized information disclosure and potential account compromise. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk.
Original NVD Description
The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps.