CVE-2026-40772: WordPress GeekyBot plugin <= 1.2.2 - Arbitrary File Upload vulnerability
Published Jun 15, 2026
·Updated
Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions.
Affected Software
1 affected component
GeekyBot GeekyBot (WordPress plugin)<=1.2.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress GeekyBot pluginto a version that resolves this vulnerability.Fixed in 1.2.3
Event History
Jun 15, 2026
CVE Published
via MITRE·08:18 PM
Data Sourced
via MITRE·08:18 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-40772?
CVE-2026-40772 has a critical severity rating of 10.
2
What is the primary risk associated with CVE-2026-40772?
CVE-2026-40772 poses a risk of unauthenticated arbitrary file upload on affected versions.
3
How do I fix CVE-2026-40772?
To fix CVE-2026-40772, update the GeekyBot plugin to version 1.2.3 or later.
4
Which versions of the GeekyBot plugin are affected by CVE-2026-40772?
CVE-2026-40772 affects GeekyBot plugin versions 1.2.2 and earlier.
5
What type of vulnerability is CVE-2026-40772 classified as?
CVE-2026-40772 is classified as a malicious file upload vulnerability.