CVE-2026-3456 is an SQL injection vulnerability in the GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress. Affected versions up to and including 1.2.0 improperly handle the user-controlled 'attributekey' parameter due to insufficient escaping and inadequate use of prepared SQL statements. This flaw allows attacker-supplied input to be appended to an existing SQL query, enabling unauthorized manipulation of backend database queries and exposure of sensitive information stored by the WordPress site.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small proof-of-concept demonstrating an OAuth2 PKCE race condition leading to possible account takeover. It contains two Python programs: a deliberately vulnerable authorization server (vulnerable_auth_server.py) and a client-side exploit/demo script (race_condition_exploit.py), plus a README and license. The vulnerable server listens on 0.0.0.0:5000 and exposes /authorize and /token. /authorize generates an authorization code and redirects to the supplied redirect_uri with code and state parameters. /token incorrectly validates the PKCE verifier, issues an access token, then waits 0.1 seconds before deleting the authorization code, creating a TOCTOU/race window where the same code may still be redeemable. The exploit script simulates a victim authorization flow, extracts the issued code from the redirect Location header, and launches concurrent redemption attempts against /token to demonstrate the race. Although the script comments discuss brute-forcing or guessing a verifier, the actual code uses one attacker thread with a hardcoded wrong_verifier and one victim thread with the correct verifier; therefore the repository mainly demonstrates the vulnerable flow and race timing rather than a full practical PKCE bypass. No reusable post-exploitation payload is included. Overall, this is a local web/network POC for studying improper authorization-code invalidation in OAuth2 PKCE implementations.
6 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.