HIGH
gingerplugins
CVE published 2026-09-11
CVE-2026-15462
The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This vulnerability allows unauthenticated attackers to inject malicious SQL queries, potentially leading to data breaches or other security incidents. WordPress administrators and defenders should assess t [truncated]