Impact
The vulnerability is an unauthenticated Cross Site Scripting flaw in the WordPress GeekyBot plugin, affecting all releases up to and including 1.2.6. An attacker can inject arbitrary JavaScript into pages that users view, potentially hijacking sessions, stealing credentials, defacing site content, or facilitating further attacks such as malware distribution. The weakness stems from insufficient input validation and is identified with CWE‑79.
Affected Systems
WordPress sites running the GeekyBot plugin by AhmadGB, version 1.2.6 or earlier, are affected. Current or earlier versions of this plugin do not address the flaw.
Risk and Exploitability
The CVSS score of 7.1 places this vulnerability in the high severity range. The EPSS score is not available, so the precise exploitation probability cannot be quantified. Because the flaw is unauthenticated and is triggered via normal HTTP requests to the plugin’s interfaces, any web visitor can exploit it. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known mass exploitation at the time of analysis.
OpenCVE Enrichment