Back to overview

CVE-2026-5294

CRITICAL
9.8
CVSS 3.1
Description
The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. This is due to a nopriv AJAX route allowing attacker-controlled model/function dispatch and reaching a plugin installer helper that downloads and unzips attacker-supplied ZIP files into wp-content/plugins/. This makes it possible for unauthenticated attackers to perform arbitrary plugin installation and achieve remote code execution.

Metadata

CVE ID
CVE-2026-5294
State
PUBLISHED
Assigner
Wordfence
Reserved
2026-03-31 22:56 UTC
Published
2026-05-05 03:37 UTC
Last updated
2026-05-06 12:31 UTC
Primary CWE
CWE-862
CWE-862 Missing Authorization
Vendor / Product
ahmadgb / GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
ahmadgb GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content 0 ≤ 1.2.2
Weakness (CWE)
CWESourceDescription
CWE-862 cna CWE-862 Missing Authorization
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview