Impact
The GeekyBot plugin contains a stored XSS flaw in its chat message field. An unauthenticated user can submit malicious scripts that are saved and later executed when an administrator views the chat history, compromising the administrative session. This flaw results in code execution within the context of the admin user and can lead to credential theft, defacement, or further exploitation.
Affected Systems
WordPress installations running the GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin, any version up to and including 1.1.8.
Risk and Exploitability
The CVSS score for this vulnerability is 7.2, indicating high severity. Its EPSS score is below 1 %, showing low probability of exploitation at present, but the flaw is not listed in KEV. Exploitation requires unauthenticated submission of a crafted chat message; the attacker then waits for an administrator to load the chat history to trigger script execution.
OpenCVE Enrichment