Junglewise Threat Intelligence

CVE-2026-57679: Ahmadgb GeekyBot SQL injection

CVE-2026-57679 · Severity: critical · CVSS 9.3 · Published 2026-07-02

Technologies: Ahmadgb GeekyBot.

Executive brief

GeekyBot, a WordPress plugin, contains a critical security flaw that allows unauthorized individuals to access the website's database. An attacker could use this to steal sensitive customer information, modify site content, or disrupt operations. This vulnerability is particularly dangerous because it can be exploited remotely without needing any login credentials.

Technical details

GeekyBot versions 1.2.5 and below are vulnerable to an unauthenticated SQL injection (CWE-89). The vulnerability exists due to improper neutralization of special elements used in SQL commands, allowing a remote attacker to send crafted queries to the database without authentication. With a CVSS score of 9.3, this flaw allows for high confidentiality impact, potentially leading to full database exfiltration. The issue is resolved in version 1.2.6.

Affected products

  • Ahmadgb GeekyBot <= 1.2.5

Timeline

  • 2026-06-04: other: Reported by researcher daroo
  • 2026-06-29: advisory: Patchstack advisory published
  • 2026-07-02: disclosed: CVE published to NVD

References