SQL Injection Vulnerability in GeekyBot Plugin for WordPress
CVE-2026-3456

7.5HIGH

What is CVE-2026-3456?

The GeekyBot plugin for WordPress allows unauthenticated users to exploit a SQL Injection vulnerability through the 'attributekey' parameter. This issue arises from inadequate escaping of user-supplied data and insufficient preparation of the SQL query, enabling attackers to inject malicious SQL commands. As a result, they can manipulate the database to extract sensitive information without the need for authentication, putting websites at risk of data exposure.

Affected Version(s)

GeekyBot β€” AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content 0 <= 1.2.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Ngoc Duc
.