


Perceptive Security
SOC/SIEM Consultancy

Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions.
Published:
1 juli 2026 om 22:00:00
Alert date:
2 juli 2026 om 14:04:36
Source:
nvd.nist.gov
Web Technologies, Database & Storage
CVE-2026-57679 describes an unauthenticated SQL injection vulnerability affecting the GeekyBot WordPress plugin in versions 1.2.5 and below. The vulnerability allows unauthenticated attackers to inject malicious SQL queries, potentially leading to unauthorized database access, data exfiltration, or manipulation. No authentication is required to exploit this flaw, making it particularly dangerous on publicly accessible WordPress installations. The issue was documented by both the NVD and Patchstack, a known WordPress security tracking service. Users of the GeekyBot plugin are advised to update to a patched version immediately. SQL injection vulnerabilities of this type are considered high severity due to the potential for complete database compromise.
Technical details
Mitigation steps:
Affected products:
GeekyBot WordPress Plugin <= 1.2.5
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-57679
https://patchstack.com/database/wordpress/plugin/geeky-bot/vulnerability/wordpress-geekybot-plugin-1-2-5-sql-injection-vulnerability?_s_id=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
