WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Geeky Bot – AI Sales Assistant for WooCommerce

WooCommerce AI sales assistant for natural product discovery, grounded answers, recommendations, and guided shopping.

8Reported vulnerabilities
9.8Highest CVSS score
2.0.1Latest version
6,000+Active installs

What to do now

Update Geeky Bot – AI Sales Assistant for WooCommerce to 1.2.7 or later. 8 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 17, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2026-5294 Critical 9.8 0.5% 0 to 1.2.2 (inclusive) 1.2.3 May 5, 2026
CVE-2026-40772 High 8.8 0.4% 1.2.2 and earlier 1.2.3 April 21, 2026
CVE-2026-57679 High 7.5 0.4% 1.2.5 and earlier 1.2.6 June 29, 2026
CVE-2026-3456 High 7.5 0.3% 0 to 1.2.0 (inclusive) 1.2.1 May 5, 2026
CVE-2026-39519 High 7.5 0.3% 1.2.0 and earlier 1.2.1 April 8, 2026
CVE-2025-15266 High 7.2 0.3% 0 to 1.1.8 (inclusive) 1.1.9 January 14, 2026
CVE-2026-61965 High 7.2 0.2% 1.2.6 and earlier 1.2.7 August 6, 2026
CVE-2026-15048 Medium 5.3 0.3% 1.2.7 and earlier 1.2.8 July 13, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.