CVE-2026-15048: Unknown Geeky Bot

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps.

Affected products

  • Unknown Geeky Bot: before 1.2.8 (fixed in 1.2.8)

Published 2026-07-31. Last modified 2026-08-26.