SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-15048

HIGH · CVSS 7.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

The Geeky Bot WordPress plugin prior to version 1.2.8 is vulnerable due to a lack of authorization checks on specific AJAX actions, enabling unauthenticated users to access sensitive chat-history session metadata, including WordPress usernames and user IDs. This exposure can lead to unauthorized information disclosure and potential account compromise. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk.

CVE
CVE-2026-15048
Severity
HIGH
CVSS
7.5
EPSS
0.26%
WordPress

Original NVD Description

The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps.