CVE-2026-32579: WordPress Kognetiks Chatbot for WordPress plugin <= 2.4.9 - Arbitrary File Upload vulnerability
Published Oct 6, 2026
·Updated
Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions.
Affected Software
1 affected component
Kognetiks Chatbot for WordPress<=2.4.9
Event History
Oct 6, 2026
CVE Published
via MITRE·08:34 AM
Data Sourced
via MITRE·08:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated remote attacker can exploit the vulnerability; no WordPress account or user interaction is required.
2
Which installations are affected?
Kognetiks Chatbot for WordPress versions 2.4.9 and earlier are affected.
3
What is the likely impact of successful exploitation?
Successful exploitation allows arbitrary file upload. The reported severity is critical, with high confidentiality, integrity, and availability impact.