Impact
An unauthenticated SQL Injection vulnerability exists in the WordPress GeekyBot plugin up to version 1.2.5, allowing an attacker to inject arbitrary SQL statements via HTTP requests. The flaw is identified as CWE‑89 and permits execution of unintended database queries.
Affected Systems
The issue impacts WordPress sites that use the GeekyBot plugin through 1.2.5; no other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score is 9.3, marking the vulnerability as critical. The EPSS score is below 1%, indicating a very low but nonzero chance of exploitation. It is not listed in CISA’s KEV catalog. The likely HTTP request carrying malicious SQL payload, inferred from the description. Attackers can exploit the flaw without prior credentials.
OpenCVE Enrichment