Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-3456: SQL injection in WordPress GeekyBot AI chatbot plugin

The GeekyBot AI content and chatbot/lead generation plugin for WordPress is vulnerable to SQL injection via the 'attributekey' parameter in versions up to and including 1.2.0, allowing unauthenticated attackers to extract sensitive database information.

Disclosed 5 May 2026 · Record updated 13 September 2026

Impact

Unauthenticated attackers can append SQL queries to existing queries to extract sensitive information from the site database.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-3456