Executive brief
GeekyBot, a WordPress plugin, contains a critical security flaw that allows unauthorized individuals to upload malicious files to a website. This could allow an attacker to take complete control of the site, steal sensitive data, or disrupt operations. Website owners should immediately update the plugin to version 1.2.3 to prevent potential compromise.
Technical details
The GeekyBot plugin for WordPress (versions 1.2.2 and below) suffers from an unrestricted file upload vulnerability (CWE-434). The flaw allows an unauthenticated remote attacker to upload files of any type, including executable scripts (backdoors), to the server. This occurs due to insufficient validation of file extensions and user permissions during the upload process. Successful exploitation grants the attacker the ability to execute arbitrary code in the context of the web server, leading to full site compromise. A patch is available in version 1.2.3.
Affected products
- Ahmad GeekyBot <= 1.2.2
Timeline
- 2026-03-09: other: Reported by Nguyen Ba Khanh
- 2026-04-21: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date
- 2026-04-21: patched: Version 1.2.3 released