PatchSiren

Geeky Bot CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Geeky Bot CVE published 2026-07-31

CVE-2026-15048

The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps. This vulnerability has a CVSS score of 7.5 and is rated HIGH. Affected product deployments should be identified and prioritized for patching. The CVE record was publi [truncated]