HIGH
Geeky Bot
CVE published 2026-07-31
CVE-2026-15048
The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps. This vulnerability has a CVSS score of 7.5 and is rated HIGH. Affected product deployments should be identified and prioritized for patching. The CVE record was publi [truncated]