CVE-2026-3456Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to SQL Injection via the 'attributekey' parameter in versions up to, and including, 1.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Disclose: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-05-05); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-05: 1Mentions · 2026-05-18: 1Mentions · 2026-06-28: 1Patch / Workaround · 2026-06-28: 1Technical Details · 2026-06-28: 105-0505-1806-28
Signal classification3 categories
Disclosure
133.3%
Disclose
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-051
Disclosure1
2026-05-181
Disclose1
2026-06-281
Patch1
Full discourse3 posts
  • Donweb Media@DonwebMedia
    Patch

    ¿Tenés una tienda en WooCommerce 9.0? Hay un RCE crítico (CVE-2026-3456) que no necesita autenticación. Parchealo en 20 minutos con esta guía antes de que los datos de tus clientes vuelen. 👇 https://seguridadenwordpress.com/cve-2026-3456-woocommerce-guia-parcheo-urgente/

    Post summary

    The post alerts users of WooCommerce 9.0 to a critical remote code execution vulnerability (CVE‑2026‑3456) that requires no authentication, and directs them to a guide for patching the issue within 20 minutes.

    0000044
    4 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclose

    【脆弱性情報】 CVE-2026-3456 GeekyBotの脆弱性について #cybernote #ブログ仲間と繋がりたい #Webライター https://www.cybernote.click/2026/05/18/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-3456-geekybot%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6/

    Post summary

    A short post announces the existence of CVE‑2026‑3456 affecting GeekyBot but provides no technical, exploit, patch, or exploitation activity details.

    0000059
    206 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-3456 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3456 #CVE-2026-3456 #CVE #High #Wordpress #CyberSecurity #InfoSec https://t.co/h3shXJz9kM

    Post summary

    The tweet announces a newly listed WordPress CVE with a severity rating and high risk level, linking to the NVD entry, but provides no technical details, exploits, or mitigation steps.

    0000053
    151 followersView on X

Explore more