CVE-2026-5294Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. This is due to a nopriv AJAX route allowing attacker-controlled model/function dispatch and reaching a plugin installer helper that downloads and unzips attacker-supplied ZIP files into wp-content/plugins/. This makes it possible for unauthenticated attackers to perform arbitrary plugin installation and achieve remote code execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-05-05); latest day: 1
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01223Mentions · 2026-05-05: 3Mentions · 2026-05-14: 3Mentions · 2026-05-16: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-16: 1Technical Details · 2026-05-05: 2Technical Details · 2026-05-14: 2Technical Details · 2026-05-16: 105-0505-1405-16
Signal classification3 categories
Disclosure
342.9%
General
228.6%
Patch
228.6%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-053
Disclosure1General1Patch1
2026-05-143
Disclosure2General1
2026-05-161
Patch1
Full discourse7 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-5294 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2.

    Post summary

    The entry announces a critical missing authorization flaw in Geeky Bot WordPress plugin (v1.2.2), providing CVSS metrics and severity but no exploit, patch, or active usage details.

    1000029
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVSS 9.8 CRITICAL · CVE-2026-5294 · 9.8 → 1.2.2 CVE: CVE-2026-5294 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The announcement identifies CVE-2026-5294 as a critical vulnerability with a CVSS score of 9.8, but does not provide any PoC, exploit, or mitigation details.

    1000029
    210 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-5294 — CVSS 9.8/10 ██████████ The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. This... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/ZRyZjUOYok

    Post summary

    The WordPress Geeky Bot plugin is critically vulnerable to missing authorization (CVE‑2026‑5294); a patch has been released to address the issue.

    1000073
    26 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    A critical vulnerability (CVE-2026-5294) affects Geeky Bot WordPress plugin ≤1.2.2, allowing unauthenticated remote code execution via plugin installation. SMBs using this plugin should update immediately or disable it to prevent breaches. #Cybersecurity

    Post summary

    The tweet declares a critical RCE flaw in the Geeky Bot WordPress plugin and urges users to update or disable the plugin, but provides no evidence of exploits, active attacks, or PoC details.

    0000073
    80 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-5294-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The content references CVE‑2026‑5294 via a URL but provides no further details, findings, or actionable information about the vulnerability.

    0000017
    210 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-5294 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5294 #CVE-2026-5294 #CVE #Critical #Wordpress #CyberSecurity #InfoSec https://t.co/WE356GCg8E

    Post summary

    The tweet announces a critical WordPress vulnerability (CVE‑2026‑5294) but offers no technical details, PoC links, or evidence of exploitation.

    0000044
    151 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5294 Missing Authorization in Geeky Bot WordPress Plugin Enables Arbitrary Plugin Installation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5294

    Post summary

    The statement announces CVE-2026-5294, describing a missing authorization flaw in the Geeky Bot WordPress plugin that allows arbitrary plugin installation; no PoC, exploit, or patch details are provided.

    0000035
    4.0K followersView on X

Explore more