
SecAlerts@SecAlertsCo
Patch
📁 CVE-2026-40772: Unauthenticated arbitrary file upload in the WordPress GeekyBot plugin <= 1.2.2. CVSS 10 critical - no auth needed to upload malicious files, likely full RCE. Update or remove immediately. #WordPress #cybersecurity https://secalerts.co/vulnerability/CVE-2026-40772 https://t.co/Ae7LMJzYur
Post summary
The tweet alerts that CVE‑2026‑40772 allows unauthenticated file uploads in the WordPress GeekyBot plugin, potentially leading to full RCE, and urges users to update or remove the plugin immediately.
0000065
836 followersView on X
