CVE-2026-5294
|
| |
|
|
Software afectado |
WORDPRESS |
|
|
|
The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. This is due to a nopriv AJAX route allowing attacker-controlled model/function dispatch and reaching a plugin installer helper that downloads and unzips attacker-supplied ZIP files into wp-content/plugins/. This makes it possible for unauthenticated attackers to perform arbitrary plugin installation and achieve remote code execution. |
Link: |
| https://nvd.nist.gov/vuln/detail/CVE-2026-5294 |