SQL Injection Vulnerability in GeekyBot Plugin for WordPress
CVE-2026-3456
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 May 2026
What is CVE-2026-3456?
The GeekyBot plugin for WordPress allows unauthenticated users to exploit a SQL Injection vulnerability through the 'attributekey' parameter. This issue arises from inadequate escaping of user-supplied data and insufficient preparation of the SQL query, enabling attackers to inject malicious SQL commands. As a result, they can manipulate the database to extract sensitive information without the need for authentication, putting websites at risk of data exposure.
Affected Version(s)
GeekyBot β AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content 0 <= 1.2.0