Junglewise Threat Intelligence

CVE-2026-39519: Ahmad GeekyBot SQL injection

CVE-2026-39519 · Severity: critical · CVSS 9.3 · Published 2026-06-15

Technologies: Ahmad-S-S GeekyBot. Vendors: Ahmad-S-S, Ahmad.

Executive brief

GeekyBot, a WordPress plugin, contains a critical security flaw that allows unauthorized individuals to access its underlying database. An attacker could use this to steal sensitive information or disrupt website operations without needing any login credentials. This type of vulnerability is frequently targeted in automated mass-exploitation campaigns against websites.

Technical details

A SQL injection vulnerability exists in the GeekyBot plugin for WordPress (versions <= 1.2.0) due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is exploitable by unauthenticated remote attackers over the network with low complexity and no user interaction required. Successful exploitation allows an attacker to directly interact with the database, potentially leading to the exfiltration of sensitive data or limited impact on availability. The issue is resolved in version 1.2.1.

Affected products

  • Ahmad GeekyBot <= 1.2.0

Timeline

  • 2026-01-28: other: Reported by Nguyen Ba Khanh
  • 2026-04-08: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date

References

Related threats