CVE-2026-15048

NONE EPSS 0.14%
Updated Jul 31, 2026
Unknown
Parameter Value
Affected Versions before 1.2.8
Type CWE-200 Information Exposure
Vendor Unknown
Public PoC No

The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps.

Weakness Type (CWE)

Vulnerable Products

unknown:geeky bot