CVE-2026-3456: SQL injection in WordPress GeekyBot AI chatbot plugin
The GeekyBot AI content and chatbot/lead generation plugin for WordPress is vulnerable to SQL injection via the 'attributekey' parameter in versions up to and including 1.2.0, allowing unauthenticated attackers to extract sensitive database information.
Disclosed 5 May 2026 · Record updated 13 September 2026
Impact
Unauthenticated attackers can append SQL queries to existing queries to extract sensitive information from the site database.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-3456
