Description
Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions.
Published: 2026-08-13
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated Cross Site Scripting flaw in the WordPress GeekyBot plugin, affecting all releases up to and including 1.2.6. An attacker can inject arbitrary JavaScript into pages that users view, potentially hijacking sessions, stealing credentials, defacing site content, or facilitating further attacks such as malware distribution. The weakness stems from insufficient input validation and is identified with CWE‑79.

Affected Systems

WordPress sites running the GeekyBot plugin by AhmadGB, version 1.2.6 or earlier, are affected. Current or earlier versions of this plugin do not address the flaw.

Risk and Exploitability

The CVSS score of 7.1 places this vulnerability in the high severity range. The EPSS score is not available, so the precise exploitation probability cannot be quantified. Because the flaw is unauthenticated and is triggered via normal HTTP requests to the plugin’s interfaces, any web visitor can exploit it. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known mass exploitation at the time of analysis.

Generated by OpenCVE AI on August 13, 2026 at 15:55 UTC.

Remediation

Vendor Solution

Update the WordPress GeekyBot Plugin to the latest available version (at least 1.2.7).


OpenCVE Recommended Actions

  • Update the GeekyBot plugin to version 1.2.7 or later
  • If an immediate update is not possible, disable the plugin until a patched version is deployed
  • Consider implementing a Web Application Firewall or other input‑sanitizing controls to block malicious scripts

Generated by OpenCVE AI on August 13, 2026 at 15:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions.
Title WordPress GeekyBot plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:25:50.432Z

Reserved: 2026-07-13T06:13:50.885Z

Link: CVE-2026-61965

cve-icon Vulnrichment

Updated: 2026-08-13T15:25:45.448Z

cve-icon NVD

Status : Received

Published: 2026-08-13T14:17:02.680

Modified: 2026-08-13T16:18:15.320

Link: CVE-2026-61965

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T16:00:11Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')